summaryrefslogtreecommitdiff
path: root/editors/pico
diff options
context:
space:
mode:
authorwiz <wiz>2012-08-13 06:53:06 +0000
committerwiz <wiz>2012-08-13 06:53:06 +0000
commitacc2a3ff43ce010badd83b17870a3ec1d0b5003f (patch)
treee45a6ef2ce6c171255126757683194ab7b4de5cd /editors/pico
parent4ffeb2784f96a661160b87dc89df4263ada3c1d4 (diff)
downloadpkgsrc-acc2a3ff43ce010badd83b17870a3ec1d0b5003f.tar.gz
Fix CVE-2012-3479:
When the Emacs user option `enable-local-variables' is set to `:safe' (the default value is t), Emacs should automatically refuse to evaluate `eval' forms in file-local variable sections. Due to the bug, Emacs instead automatically evaluates such `eval' forms. Thus, if the user changes the value of `enable-local-variables' to `:safe', visiting a malicious file can cause automatic execution of arbitrary Emacs Lisp code with the permissions of the user. Bug tracker ref: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=12155
Diffstat (limited to 'editors/pico')
0 files changed, 0 insertions, 0 deletions