Re: Magit-inspired Emacs interface for Sapling (sl)

swithin chan <[email protected]>
Newsgroups gmane.emacs.devel
Message-ID <[email protected]>
 Hi Mr Richard Stallman,I made a script on this to verify emacs 30.2. This bug is gone:https://github.com/swithinchan/emacsbugs/blob/main/check-cve-2024-30205.sh
  - Script checks Emacs >= 29.3 and Org >= 9.6.23.
  - It also exercises the actual fixed behavior: a TRAMP path /ssh:attacker.invalid:/tmp/evil.org is refused as unsafe, while a local Org file still loads.

  - Current run: RESULT: PASS, exit code 0.

  Run it anytime with:

  ./check-cve-2024-30205.sh

  Or target a specific Emacs binary with EMACS=/path/to/emacs ./check-cve-2024-30205.sh.

   On Monday, 31 August 2026 at 11:17:08 am GMT+8, Richard Stallman <[email protected]> wrote:  
 
 [[[ To any NSA and FBI agents reading my email: please consider    ]]]
[[[ whether defending the US Constitution against all enemies,    ]]]
[[[ foreign or domestic, requires you to follow Snowden's example. ]]]

  > I don't have a good overview of security stuff, since I don't work on
  > that, but doesn't it say:

  >  CVE-2024-30205 is a vulnerability in GNU Emacs versions prior to 29.3
  >  where Org mode treats the contents of remote files as trusted.

  > with emphasis in "prior"?

If this means that the bug is gone now, it can't hurt to verify that
it really is gone.

-- 
Dr Richard Stallman (https://stallman.org)
Chief GNUisance of the GNU Project (https://gnu.org)
Founder, Free Software Foundation (https://fsf.org)
Internet Hall-of-Famer (https://internethalloffame.org)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.