From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Chong Yidong Newsgroups: gmane.emacs.devel Subject: Re: Security flaw in enable-local-eval; new release plan Date: Tue, 14 Aug 2012 12:07:00 +0800 Message-ID: <87obme2k2j.fsf@gnu.org> References: <87obmfsczi.fsf@gnu.org> <20520.46442.225875.652089@a1i15.kph.uni-mainz.de> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: dough.gmane.org 1344917239 32724 80.91.229.3 (14 Aug 2012 04:07:19 GMT) X-Complaints-To: usenet@dough.gmane.org NNTP-Posting-Date: Tue, 14 Aug 2012 04:07:19 +0000 (UTC) Cc: emacs-devel@gnu.org To: Ulrich Mueller Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Tue Aug 14 06:07:19 2012 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1T18PQ-0004fw-GY for ged-emacs-devel@m.gmane.org; Tue, 14 Aug 2012 06:07:12 +0200 Original-Received: from localhost ([::1]:54241 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1T18PP-0007K5-5C for ged-emacs-devel@m.gmane.org; Tue, 14 Aug 2012 00:07:11 -0400 Original-Received: from eggs.gnu.org ([208.118.235.92]:57865) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1T18PM-0007K0-Jq for emacs-devel@gnu.org; Tue, 14 Aug 2012 00:07:09 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1T18PK-00068U-Mb for emacs-devel@gnu.org; Tue, 14 Aug 2012 00:07:08 -0400 Original-Received: from mail-gg0-f169.google.com ([209.85.161.169]:44152) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1T18PK-00068L-Iq for emacs-devel@gnu.org; Tue, 14 Aug 2012 00:07:06 -0400 Original-Received: by ggnf4 with SMTP id f4so4421689ggn.0 for ; Mon, 13 Aug 2012 21:07:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=sender:from:to:cc:subject:references:date:in-reply-to:message-id :user-agent:mime-version:content-type; bh=l0qekA7BAji1KPdSYkJ+hzoDoAT1uhAF2HwB+PpMCK4=; b=a5Wb7R2fsK1usvW+15Pcqk9XZ3Yo17U+5/nQY/N2bTfd85LGKQyQKcMA4KfFQ/+j46 EwXksd/qpvdrdDuJOHfTrzF6wPVHv8N4SHGxxnXceDihQ8nkVJWvDQR/llWW+EVNKUwk p0ARKUTk2i6RYSIrh+EzyNxa7rI2PRDsmAGzLkHvQYKiTn9Ab1I6NAfOp8ZkTpdsti7g Dt4sAa+baLR1HBFZjqY6I/qoD/eQrNmMLHAREhGLMht0UHpFe4QumI1c4qt/96Gi8wHC Wv1qQ1RIaHBVIcVe/tW7Dv8SDZzZdwVmejx8qMr+urrDeLA4/Vrmi7KfOS9fq9aPnWPD G+7g== Original-Received: by 10.50.213.97 with SMTP id nr1mr9238080igc.40.1344917225196; Mon, 13 Aug 2012 21:07:05 -0700 (PDT) Original-Received: from ulysses ([155.69.19.125]) by mx.google.com with ESMTPS id wg9sm3279559igb.0.2012.08.13.21.07.02 (version=SSLv3 cipher=OTHER); Mon, 13 Aug 2012 21:07:04 -0700 (PDT) In-Reply-To: <20520.46442.225875.652089@a1i15.kph.uni-mainz.de> (Ulrich Mueller's message of "Mon, 13 Aug 2012 10:06:02 +0200") User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.1 (gnu/linux) X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 209.85.161.169 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:152503 Archived-At: Ulrich Mueller writes: >>>>>> On Mon, 13 Aug 2012, Chong Yidong wrote: > >> Paul Ling has found a security flaw in the file-local variables code >> in GNU Emacs. > > Is there already a CVE number for this? Use CVE-2012-3479 for this issue.