GNU bug report logs - #30912
[bug-gnu-emacs] emacs as a route to privilege escalation

Previous Next

Package: emacs;

Reported by: "Nelson H. F. Beebe" <beebe <at> math.utah.edu>

Date: Thu, 22 Mar 2018 23:42:01 UTC

Severity: normal

Tags: notabug, security, wontfix

Merged with 28618

Done: Noam Postavsky <npostavs <at> gmail.com>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: "Nelson H. F. Beebe" <beebe <at> math.utah.edu>
To: 30912 <at> debbugs.gnu.org
Cc: beebe <at> math.utah.edu
Subject: bug#30912: [bug-gnu-emacs] emacs as a route to privilege escalation
Date: Thu, 22 Mar 2018 17:41:22 -0600
The SANS security list today carried a pointer to this Web site:

	Abusing Text Editors with Third-party Plugins
	March 15, 2018
	Dor Azouri 
	https://safebreach.com/Post/Abusing-Text-Editors-with-Third-party-Plugins

It links to an 11-page report of the same title at

	https://go.safebreach.com/rs/535-IXZ-934/images/Abusing_Text_Editors.pdf

Do emacs developers wish to respond to the security attacks described
there?

-------------------------------------------------------------------------------
- Nelson H. F. Beebe                    Tel: +1 801 581 5254                  -
- University of Utah                    FAX: +1 801 581 4148                  -
- Department of Mathematics, 110 LCB    Internet e-mail: beebe <at> math.utah.edu  -
- 155 S 1400 E RM 233                       beebe <at> acm.org  beebe <at> computer.org -
- Salt Lake City, UT 84112-0090, USA    URL: http://www.math.utah.edu/~beebe/ -
-------------------------------------------------------------------------------




This bug report was last modified 7 years and 56 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.