From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Stefan Monnier Newsgroups: gmane.emacs.bugs Subject: bug#19479: Package manager vulnerable Date: Thu, 08 Jan 2015 09:39:22 -0500 Message-ID: References: NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Trace: ger.gmane.org 1420728231 14930 80.91.229.3 (8 Jan 2015 14:43:51 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Thu, 8 Jan 2015 14:43:51 +0000 (UTC) Cc: 19479@debbugs.gnu.org To: Kelly Dean Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Thu Jan 08 15:43:45 2015 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1Y9EFy-0003Ut-Pe for geb-bug-gnu-emacs@m.gmane.org; Thu, 08 Jan 2015 15:40:14 +0100 Original-Received: from localhost ([::1]:46350 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Y9EFx-0005tt-Pz for geb-bug-gnu-emacs@m.gmane.org; Thu, 08 Jan 2015 09:40:13 -0500 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:37022) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Y9EFt-0005or-CK for bug-gnu-emacs@gnu.org; Thu, 08 Jan 2015 09:40:10 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Y9EFo-0006L7-DP for bug-gnu-emacs@gnu.org; Thu, 08 Jan 2015 09:40:09 -0500 Original-Received: from debbugs.gnu.org ([140.186.70.43]:58829) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Y9EFo-0006JK-A3 for bug-gnu-emacs@gnu.org; Thu, 08 Jan 2015 09:40:04 -0500 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.80) (envelope-from ) id 1Y9EFn-0008HO-67 for bug-gnu-emacs@gnu.org; Thu, 08 Jan 2015 09:40:03 -0500 X-Loop: help-debbugs@gnu.org Resent-From: Stefan Monnier Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Thu, 08 Jan 2015 14:40:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 19479 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: security Original-Received: via spool by 19479-submit@debbugs.gnu.org id=B19479.142072796731779 (code B ref 19479); Thu, 08 Jan 2015 14:40:02 +0000 Original-Received: (at 19479) by debbugs.gnu.org; 8 Jan 2015 14:39:27 +0000 Original-Received: from localhost ([127.0.0.1]:39962 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1Y9EFC-0008GU-Qh for submit@debbugs.gnu.org; Thu, 08 Jan 2015 09:39:27 -0500 Original-Received: from pruche.dit.umontreal.ca ([132.204.246.22]:44384) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1Y9EFA-0008GM-OE for 19479@debbugs.gnu.org; Thu, 08 Jan 2015 09:39:25 -0500 Original-Received: from pastel.home (lechon.iro.umontreal.ca [132.204.27.242]) by pruche.dit.umontreal.ca (8.14.1/8.14.1) with ESMTP id t08EdMNG018520; Thu, 8 Jan 2015 09:39:22 -0500 Original-Received: by pastel.home (Postfix, from userid 20848) id 6D8221F56; Thu, 8 Jan 2015 09:39:22 -0500 (EST) In-Reply-To: (Kelly Dean's message of "Thu, 08 Jan 2015 05:29:44 +0000") User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/25.0.50 (gnu/linux) X-NAI-Spam-Flag: NO X-NAI-Spam-Threshold: 5 X-NAI-Spam-Score: 0 X-NAI-Spam-Rules: 1 Rules triggered RV5180=0 X-NAI-Spam-Version: 2.3.0.9393 : core <5180> : inlines <1730> : streams <1370080> : uri <1841707> X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.15 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x X-Received-From: 140.186.70.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.bugs:98115 Archived-At: > of PD code is, I abided (and still abide) by your wishes. I submitted this > patch because Stefan invited me to. Maybe Stefan just forgot that you ask= ed > me not to submit any more patches, Indeed, that's the case. You're one of the very rare oddballs who can't be bothered to sign a trivial document to get this out of the way, but for the life of me, I can't remember the names of the handful of oddballs, so I keep repeating this error. > but I assumed he invited this patch because a security vulnerability > counted as a =E2=80=9Fparticular circumstance=E2=80=9D that your copyright > clerk mentioned. Emacs is full of vulnerabilities and has barely started using encryption technology to try and eliminate some of them, so no, it's definitely not "special" in this sense. And in any case the "special"ness usually doesn't refer to the usefulness of the code but rather to the fact that it'd be difficult to get this code some other way (i.e. it's both important/useful code and it'd take a while to rewrite it). Stefan