GNU bug report logs - #30190
27.0.50; term run in line mode shows user passwords

Previous Next

Package: emacs;

Reported by: Tino Calancha <tino.calancha <at> gmail.com>

Date: Sun, 21 Jan 2018 12:17:02 UTC

Severity: normal

Tags: confirmed, fixed, security

Found in versions 27.0.50, 24.3

Fixed in version 26.2

Done: Noam Postavsky <npostavs <at> gmail.com>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: Eli Zaretskii <eliz <at> gnu.org>
To: Tino Calancha <tino.calancha <at> gmail.com>
Cc: 30190 <at> debbugs.gnu.org, npostavs <at> users.sourceforge.net
Subject: bug#30190: 27.0.50; term run in line mode shows user passwords
Date: Sat, 03 Feb 2018 19:08:53 +0200
> From: Tino Calancha <tino.calancha <at> gmail.com>
> Date: Sun, 04 Feb 2018 01:15:54 +0900
> Cc: 30190 <at> debbugs.gnu.org
> 
> Noam Postavsky <npostavs <at> users.sourceforge.net> writes:
> 
> > Yes, seems to have been the case for a long time, I can reproduce back
> > to 24.3 (oldest Emacs version I have running).
> This is a security risk.  I would like to have it fixed ASAP.
> Below patch seems to work.  Any feedback would be appreciated.

My feedback is that such a radical solution with so many lines of code
is a no-no for the release branch.  Please look for a simpler
solution, perhaps don't create a new file?

Thanks.




This bug report was last modified 6 years and 357 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.