From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED.blaine.gmane.org!not-for-mail From: Stefan Kangas Newsgroups: gmane.emacs.bugs Subject: bug#37656: 27.0.50; Arbitrary code execution with special `mode:' Date: Wed, 16 Oct 2019 01:17:51 +0200 Message-ID: References: Mime-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Injection-Info: blaine.gmane.org; posting-host="blaine.gmane.org:195.159.176.226"; logging-data="103304"; mail-complaints-to="usenet@blaine.gmane.org" Cc: 37656@debbugs.gnu.org, Emacs developers To: adam plaice Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Wed Oct 16 01:19:11 2019 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([209.51.188.17]) by blaine.gmane.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from ) id 1iKW5u-000Qjt-Jq for geb-bug-gnu-emacs@m.gmane.org; Wed, 16 Oct 2019 01:19:10 +0200 Original-Received: from localhost ([::1]:33176 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1iKW5t-0007IP-8K for geb-bug-gnu-emacs@m.gmane.org; Tue, 15 Oct 2019 19:19:09 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:43869) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1iKW5n-0007Fl-9B for bug-gnu-emacs@gnu.org; Tue, 15 Oct 2019 19:19:04 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1iKW5m-00064N-Bn for bug-gnu-emacs@gnu.org; Tue, 15 Oct 2019 19:19:03 -0400 Original-Received: from debbugs.gnu.org ([209.51.188.43]:36198) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1iKW5m-00064C-8z for bug-gnu-emacs@gnu.org; Tue, 15 Oct 2019 19:19:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1iKW5m-0006TA-2b for bug-gnu-emacs@gnu.org; Tue, 15 Oct 2019 19:19:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Stefan Kangas Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Tue, 15 Oct 2019 23:19:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 37656 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: security Original-Received: via spool by 37656-submit@debbugs.gnu.org id=B37656.157118149324806 (code B ref 37656); Tue, 15 Oct 2019 23:19:02 +0000 Original-Received: (at 37656) by debbugs.gnu.org; 15 Oct 2019 23:18:13 +0000 Original-Received: from localhost ([127.0.0.1]:45019 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1iKW4z-0006S2-1P for submit@debbugs.gnu.org; Tue, 15 Oct 2019 19:18:13 -0400 Original-Received: from mail-pg1-f169.google.com ([209.85.215.169]:33778) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1iKW4v-0006Rl-LD for 37656@debbugs.gnu.org; Tue, 15 Oct 2019 19:18:11 -0400 Original-Received: by mail-pg1-f169.google.com with SMTP id i76so13078949pgc.0 for <37656@debbugs.gnu.org>; Tue, 15 Oct 2019 16:18:09 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=uy8asuFeUonxQygv5X2HT6YYit6i6IFRsw8r9Ui5FNc=; b=rJHl/YCfGBewN8/OQCJ0Q0XXNLx6c2ro4/wZJ0x73k6g4f2toMuGOPDTob9FReoK60 p4wSA6hXX3h5Qviz9DMWvDlxkevGuL7zjomIqDxaN2xYzrswrMnfXDlkz4aMJun7ibyU MB506prRjjSxFTd0bckzgJAFFX+BStQU+n3iRBIcxm0eiVIWb31+gvOV9w+7BMhZE+ag wq3RZ6/Z4ISQ6BB9XnYgRk2wcnDvGrLeQyHQ4zh1T+O6Guzp2ik93WDqvTBOic9AqN+G csBLlOhy8OgnFFAjnpDIdzGY2sha8aNi4W4DjFlJdzG9vdh7mpFA0ZoNOC9yyzC3dCgy DvfA== X-Gm-Message-State: APjAAAWjUfSD8oa2qu87P2cFlHjjQBWunHPUqi/7/Kzo/v/5nYOqrnA2 kLV2z9GjOjw8jpN+CZNJdPCjuPjAp6pZMN+yTRk= X-Google-Smtp-Source: APXvYqxZV2Q34Wqc5b4IsgMrbDfD2faJ/csMJ+fkrh4jGggnTvsIqTVxcmJEDn+Xp9LMAgau1xRMGNAvpAW4nR392q8= X-Received: by 2002:a63:4046:: with SMTP id n67mr38175017pga.200.1571181483756; Tue, 15 Oct 2019 16:18:03 -0700 (PDT) In-Reply-To: X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 209.51.188.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:169406 Archived-At: Stefan Kangas writes: > > The below patch seems to fix it by disabling the feature it exploits. > > Here is a more complete patch. Does it look like the right fix? flymake.el was first added to Emacs in version 22.1: 4bcbcb9df3 2004-05-29 Eli Zaretskii New file. The "multiple mode specification feature" dates back to: 9fa7bfe524 1993-09-11 Richard M. Stallman (hack-local-variables-prop-line): Ignore any specification for `mode:', since set-auto-mode has already handled it. (set-auto-mode): Clean up. Handle more than one `mode:' spec in -*-. The code that my proposed patch changes has stayed untouched since this 1993 commit. If we agree that disabling this feature is the solution here, a backported security fix should therefore hopefully be a one liner all the way back to version 22.1. Best regards, Stefan Kangas