On Thursday 26 February 2009, Vladimir G. Ivanovic wrote:
Absent any instruction, I will file a high priority bug. (Is it
possible mark bugs as security-related in Tracker?)
[...]
Morten Welinder reports about GNU Emacs and edit-utils in XEmacs: By
shipping a .flc accompanying a source file (.c for example) and setting
font-lock-support-mode to fast-lock-mode in the source file through
local variables, any Lisp code in the .flc file is executed without
warning (CVE-2008-2142).
This was already fixed in June, and the fix is included in edit-utils package
version 2.40 which is also in the latest sumo tarballs.
_______________________________________________
XEmacs-Beta mailing list
XEmacs-Beta(a)xemacs.org
http://calypso.tux.org/cgi-bin/mailman/listinfo/xemacs-beta