Path to this page:
Subject: CVS commit: pkgsrc/editors/emacs25/patches
From: Thomas Klausner
Date: 2017-09-11 13:33:33
Message id: 20170911113334.0C648FA98@cvs.NetBSD.org
Log Message:
emacs25: fix security issue
GNU Emacs is an extensible, customizable, free/libre text editor and software
environment. When Emacs renders MIME text/enriched data (Internet RFC 1896), it
is vulnerable to arbitrary code execution. Since Emacs-based mail clients decode
"Content-Type: text/enriched", this code is exploitable remotely. This bug
affects GNU Emacs versions 19.29 through 25.2.
Although we know no efforts to exploit this in the wild, exploitation is easy.
http://www.openwall.com/lists/oss-security/2017/09/11/1
Files: