Re: Magit-inspired Emacs interface for Sapling (sl)
swithin chan <[email protected]>
| Newsgroups | gmane.emacs.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Mr Richard Stallman,I made a script on this to verify emacs 30.2. This bug is gone:https://github.com/swithinchan/emacsbugs/blob/main/check-cve-2024-30205.sh - Script checks Emacs >= 29.3 and Org >= 9.6.23. - It also exercises the actual fixed behavior: a TRAMP path /ssh:attacker.invalid:/tmp/evil.org is refused as unsafe, while a local Org file still loads. - Current run: RESULT: PASS, exit code 0. Run it anytime with: ./check-cve-2024-30205.sh Or target a specific Emacs binary with EMACS=/path/to/emacs ./check-cve-2024-30205.sh. On Monday, 31 August 2026 at 11:17:08 am GMT+8, Richard Stallman <[email protected]> wrote: [[[ To any NSA and FBI agents reading my email: please consider ]]] [[[ whether defending the US Constitution against all enemies, ]]] [[[ foreign or domestic, requires you to follow Snowden's example. ]]] > I don't have a good overview of security stuff, since I don't work on > that, but doesn't it say: > CVE-2024-30205 is a vulnerability in GNU Emacs versions prior to 29.3 > where Org mode treats the contents of remote files as trusted. > with emphasis in "prior"? If this means that the bug is gone now, it can't hurt to verify that it really is gone. -- Dr Richard Stallman (https://stallman.org) Chief GNUisance of the GNU Project (https://gnu.org) Founder, Free Software Foundation (https://fsf.org) Internet Hall-of-Famer (https://internethalloffame.org)