From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Paul Eggert Newsgroups: gmane.emacs.devel Subject: Re: Fwd: Re: [oss-security] GNU Emacs 25.2 enriched text remote code execution Date: Wed, 13 Sep 2017 12:56:51 -0700 Organization: UCLA Computer Science Department Message-ID: <53c359ee-1594-aa9f-9c9a-a592f5ad733f@cs.ucla.edu> References: <87mv5zzt6n.fsf@mid.deneb.enyo.de> <87fubrxk2s.fsf@Niukka.kon.iki.fi> <95585f8b-3c15-1dd0-6af7-d28a743ebf0d@cs.ucla.edu> <83zi9yodvh.fsf@gnu.org> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: quoted-printable X-Trace: blaine.gmane.org 1505332666 20674 195.159.176.226 (13 Sep 2017 19:57:46 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Wed, 13 Sep 2017 19:57:46 +0000 (UTC) User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.3.0 Cc: kon@iki.fi, emacs-devel@gnu.org To: Eli Zaretskii Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Wed Sep 13 21:57:42 2017 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dsDn4-0005Hd-FH for ged-emacs-devel@m.gmane.org; Wed, 13 Sep 2017 21:57:42 +0200 Original-Received: from localhost ([::1]:44371 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dsDnB-00029y-U0 for ged-emacs-devel@m.gmane.org; Wed, 13 Sep 2017 15:57:49 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:42157) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dsDmM-00029f-VV for emacs-devel@gnu.org; Wed, 13 Sep 2017 15:56:59 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dsDmM-0006Gr-9J for emacs-devel@gnu.org; Wed, 13 Sep 2017 15:56:59 -0400 Original-Received: from zimbra.cs.ucla.edu ([131.179.128.68]:37968) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1dsDmI-00060S-Ie; Wed, 13 Sep 2017 15:56:54 -0400 Original-Received: from localhost (localhost [127.0.0.1]) by zimbra.cs.ucla.edu (Postfix) with ESMTP id CAFC3160CED; Wed, 13 Sep 2017 12:56:52 -0700 (PDT) Original-Received: from zimbra.cs.ucla.edu ([127.0.0.1]) by localhost (zimbra.cs.ucla.edu [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id H1_PWgWoADWR; Wed, 13 Sep 2017 12:56:52 -0700 (PDT) Original-Received: from localhost (localhost [127.0.0.1]) by zimbra.cs.ucla.edu (Postfix) with ESMTP id 1D73D160CFC; Wed, 13 Sep 2017 12:56:52 -0700 (PDT) X-Virus-Scanned: amavisd-new at zimbra.cs.ucla.edu Original-Received: from zimbra.cs.ucla.edu ([127.0.0.1]) by localhost (zimbra.cs.ucla.edu [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id ipyIJHXJ_sKj; Wed, 13 Sep 2017 12:56:52 -0700 (PDT) Original-Received: from Penguin.CS.UCLA.EDU (Penguin.CS.UCLA.EDU [131.179.64.200]) by zimbra.cs.ucla.edu (Postfix) with ESMTPSA id F2ED8160988; Wed, 13 Sep 2017 12:56:51 -0700 (PDT) In-Reply-To: <83zi9yodvh.fsf@gnu.org> Content-Language: en-US X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x [fuzzy] X-Received-From: 131.179.128.68 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.org gmane.emacs.devel:218217 Archived-At: On 09/13/2017 07:46 AM, Eli Zaretskii wrote: >> that if nobody has a better suggestion. > I only have 21.4, and there the recipe in the 25.3 NEWS works. Can we > please see the exact recipe tried in Emacs 21.3 and its results? I did not reproduce the problem on Solaris 10 sparc, which ships with=20 GNU Emacs 21.3 in /opt/sfw/bin/emacs (dated 2006-03-26). I ran the shell=20 command "Emacs" from a terminal window, where my ~/.emacs file contained=20 only this: =C2=A0 (eval-after-load "enriched" =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 '(defun enriched-decode-display-prop (sta= rt end &optional param) =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= (list start end))) which is what is in 25.3 etc/NEWS. Emacs started up fine and the bugfix=20 was in place. So perhaps we should leave the NEWS file alone. It's hard to reproduce the problem on today's GNU/Linux, as these old=20 releases no longer build out of the box.