From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Eli Zaretskii Newsgroups: gmane.emacs.devel Subject: Re: [ANNOUNCE] Emacs 25.3 released Date: Tue, 12 Sep 2017 19:42:45 +0300 Message-ID: <83tw07q35m.fsf@gnu.org> References: <87wp55t0un.fsf@petton.fr> <87tw07kikp.fsf@gnu.org> Reply-To: Eli Zaretskii NNTP-Posting-Host: blaine.gmane.org X-Trace: blaine.gmane.org 1505235062 4817 195.159.176.226 (12 Sep 2017 16:51:02 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Tue, 12 Sep 2017 16:51:02 +0000 (UTC) Cc: emacs-devel@gnu.org To: Roland Winkler Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Tue Sep 12 18:50:58 2017 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1droOg-0000gz-12 for ged-emacs-devel@m.gmane.org; Tue, 12 Sep 2017 18:50:50 +0200 Original-Received: from localhost ([::1]:37416 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1droOn-0000Yi-8k for ged-emacs-devel@m.gmane.org; Tue, 12 Sep 2017 12:50:57 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:54214) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1droGx-0002B5-QB for emacs-devel@gnu.org; Tue, 12 Sep 2017 12:42:52 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1droGu-0001LV-Ik for emacs-devel@gnu.org; Tue, 12 Sep 2017 12:42:51 -0400 Original-Received: from fencepost.gnu.org ([2001:4830:134:3::e]:40031) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1droGu-0001LK-Fc for emacs-devel@gnu.org; Tue, 12 Sep 2017 12:42:48 -0400 Original-Received: from 84.94.185.246.cable.012.net.il ([84.94.185.246]:2277 helo=home-c4e4a596f7) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) (envelope-from ) id 1droGt-00040l-Ef; Tue, 12 Sep 2017 12:42:48 -0400 In-reply-to: <87tw07kikp.fsf@gnu.org> (message from Roland Winkler on Tue, 12 Sep 2017 11:06:14 -0500) X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 2001:4830:134:3::e X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.org gmane.emacs.devel:218135 Archived-At: > From: Roland Winkler > Date: Tue, 12 Sep 2017 11:06:14 -0500 > > > (eval-after-load "enriched" > > '(defun enriched-decode-display-prop (start end &optional param) > > (list start end))) > > Many users may have the problem that they cannot upgrade immediately to > 25.3. Is it fair to say that putting the above lines of code in > ~/.emacs fully protects the user from the vulnerability? Yes, it does. > If yes, we may want to advertise these lines of code more broadly. Please feel free to do that. > Or do the above lines of code provide only an incomplete fix? It's a complete fix, in the sense that it completely removes the vulnerability, by disabling processing of 'display' properties in Enriched text.