From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: David Kastrup Newsgroups: gmane.emacs.devel Subject: Re: Percent sign in message Date: Tue, 19 Sep 2006 23:49:25 +0200 Message-ID: <85slinbk7u.fsf@lola.goethe.zz> References: <200609110657.k8B6vTHW021987@ushabti.sfbay.sun.com> <85mz96c1m9.fsf@lola.goethe.zz> <85irjt9juq.fsf@lola.goethe.zz> <33680.128.165.123.18.1158694771.squirrel@webmail.lanl.gov> NNTP-Posting-Host: main.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Trace: sea.gmane.org 1158704404 1067 80.91.229.2 (19 Sep 2006 22:20:04 GMT) X-Complaints-To: usenet@sea.gmane.org NNTP-Posting-Date: Tue, 19 Sep 2006 22:20:04 +0000 (UTC) Cc: emacs-devel@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Wed Sep 20 00:20:03 2006 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([199.232.76.165]) by ciao.gmane.org with esmtp (Exim 4.43) id 1GPnwg-00050g-N4 for ged-emacs-devel@m.gmane.org; Wed, 20 Sep 2006 00:20:02 +0200 Original-Received: from localhost ([127.0.0.1] helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1GPnwf-0000qG-Va for ged-emacs-devel@m.gmane.org; Tue, 19 Sep 2006 18:20:02 -0400 Original-Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1GPnwT-0000mx-Gq for emacs-devel@gnu.org; Tue, 19 Sep 2006 18:19:49 -0400 Original-Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1GPnwS-0000lM-PE for emacs-devel@gnu.org; Tue, 19 Sep 2006 18:19:48 -0400 Original-Received: from [199.232.76.173] (helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1GPnwS-0000lC-Jx for emacs-devel@gnu.org; Tue, 19 Sep 2006 18:19:48 -0400 Original-Received: from [199.232.76.164] (helo=fencepost.gnu.org) by monty-python.gnu.org with esmtp (Exim 4.52) id 1GPnzc-0005EQ-9B for emacs-devel@gnu.org; Tue, 19 Sep 2006 18:23:04 -0400 Original-Received: from localhost ([127.0.0.1] helo=lola.goethe.zz) by fencepost.gnu.org with esmtp (Exim 4.34) id 1GPnwR-0005wx-U0; Tue, 19 Sep 2006 18:19:48 -0400 Original-Received: by lola.goethe.zz (Postfix, from userid 1002) id E35281C40B5C; Tue, 19 Sep 2006 23:49:25 +0200 (CEST) Original-To: herring@lanl.gov In-Reply-To: <33680.128.165.123.18.1158694771.squirrel@webmail.lanl.gov> (Stuart D. Herring's message of "Tue\, 19 Sep 2006 12\:39\:31 -0700 \(PDT\)") User-Agent: Gnus/5.11 (Gnus v5.11) Emacs/22.0.50 (gnu/linux) X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:60018 Archived-At: "Stuart D. Herring" writes: >> I'd want to mention that format string vulnerabilities are a common >> attack vector for viruses. They will not likely be exploitable in >> Elisp, but it shows that they are not rare among programmers (indeed, >> one such case prompted the release of Emacs 21.4), and could cause >> weird effects. > > This is off-topic, but what was the case that prompted 21.4? I've never > seen it described. Well, the diff is short enough. A format string vulnerability in the movemail executable. -- David Kastrup, Kriemhildstr. 15, 44793 Bochum