GNU bug report logs - #17839
24.4.50; read-passwd echoes password input in non-interactive sessions

Previous Next

Package: emacs;

Reported by: Sebastian Wiesner <swiesner <at> lunaryorn.com>

Date: Mon, 23 Jun 2014 15:37:02 UTC

Severity: normal

Found in version 24.4.50

Fixed in version 24.4

Done: Glenn Morris <rgm <at> gnu.org>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: Stefan Monnier <monnier <at> iro.umontreal.ca>
To: Sebastian Wiesner <swiesner <at> lunaryorn.com>
Cc: schwab <at> suse.de, Eli Zaretskii <eliz <at> gnu.org>, 17839 <at> debbugs.gnu.org, Michael Albinus <michael.albinus <at> gmx.de>
Subject: bug#17839: 24.4.50; read-passwd echoes password input in non-interactive sessions
Date: Thu, 07 Aug 2014 09:01:49 -0400
> I know, but I'd argue that since it's kind of a security issue, albeit
> small,  it deserves a timely fix.  YMMV, though, and I'm ok with
> either decision you  make.

I'm OK with installing a fix for it in emacs-24, but the fix we have in
trunk is not "obviously safe" enough to be appropriate for emacs-24.
And I think the warning we added to emacs-24 is a sufficient (tho not
ideal) stop-gap for emacs-24.

IOW feel free to send a safer patch (with corresponding copyright
paperwork, of course),


        Stefan




This bug report was last modified 10 years and 295 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.