unofficial mirror of emacs-devel@gnu.org 
 help / color / mirror / code / Atom feed
* Security advisory?
@ 2007-06-22 20:25 Chong Yidong
  2007-06-22 20:46 ` Glenn Morris
  2007-06-22 22:17 ` Security advisory? Thien-Thi Nguyen
  0 siblings, 2 replies; 4+ messages in thread
From: Chong Yidong @ 2007-06-22 20:25 UTC (permalink / raw)
  To: emacs-devel

I notice that Mandriva has announced a security advisory for Emacs
21.4, because "a vulnerability in emacs was discovered where it would
crash when processing certain types of images."  This bug is being
files as a DoS (denial of service) vulnerability:

http://www.securityfocus.com/archive/1/471992/30/0/threaded

Does anyone know what the heck this is about?

Over the course of the Emacs 22 release cycle, we have accumulated
literally hundreds of ways to crash Emacs 21.4, some more esoteric
than others.  These are fixed in Emacs 22, not Emacs 21, so if anyone
wanted to, he or she could go through the emacs-devel archives for the
last couple of years, locate these crasher bugs, and file hundreds of
these "security advisories".  So it seems peculiar for this vendor to
single out one particular bug.

IMO, calling a bug that causes Emacs to crash a "denial of service
vulnerability" is little more than a silly example of
computer-security imperialism.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2007-06-23 16:44 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-06-22 20:25 Security advisory? Chong Yidong
2007-06-22 20:46 ` Glenn Morris
2007-06-23 16:44   ` Automatic display of images (was: Security advisory?) Reiner Steib
2007-06-22 22:17 ` Security advisory? Thien-Thi Nguyen

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/emacs.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).