Github messages for voidlinux
 help / color / mirror / Atom feed
* [ISSUE] vim arbitrary code execution via modeline
@ 2019-06-04 23:16 voidlinux-github
  2019-06-04 23:40 ` voidlinux-github
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: voidlinux-github @ 2019-06-04 23:16 UTC (permalink / raw)
  To: ml

[-- Attachment #1: Type: text/plain, Size: 209 bytes --]

New issue by congdanhqx on void-packages repository

https://github.com/void-linux/void-packages/issues/12152
Description: See https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: vim arbitrary code execution via modeline
  2019-06-04 23:16 [ISSUE] vim arbitrary code execution via modeline voidlinux-github
@ 2019-06-04 23:40 ` voidlinux-github
  2019-06-05  0:51 ` voidlinux-github
                   ` (2 subsequent siblings)
  3 siblings, 0 replies; 5+ messages in thread
From: voidlinux-github @ 2019-06-04 23:40 UTC (permalink / raw)
  To: ml

[-- Attachment #1: Type: text/plain, Size: 205 bytes --]

New comment by CameronNemo on void-packages repository

https://github.com/void-linux/void-packages/issues/12152#issuecomment-498882918
Comment:
Why do we not just disable this dumpster fire of a feature?

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: vim arbitrary code execution via modeline
  2019-06-04 23:16 [ISSUE] vim arbitrary code execution via modeline voidlinux-github
  2019-06-04 23:40 ` voidlinux-github
@ 2019-06-05  0:51 ` voidlinux-github
  2019-06-05  7:39 ` voidlinux-github
  2019-06-05  7:58 ` [ISSUE] [CLOSED] " voidlinux-github
  3 siblings, 0 replies; 5+ messages in thread
From: voidlinux-github @ 2019-06-05  0:51 UTC (permalink / raw)
  To: ml

[-- Attachment #1: Type: text/plain, Size: 364 bytes --]

New comment by congdanhqx on void-packages repository

https://github.com/void-linux/void-packages/issues/12152#issuecomment-498896336
Comment:
On 2019-06-04 16:40:13 -0700, Cameron Nemo wrote:
> Why do we not just disable this dumpster fire of a feature?

modeline is useful for setting filetype, encoding, spacing,
we can't disable modelineexpr until v8.1.1366


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: vim arbitrary code execution via modeline
  2019-06-04 23:16 [ISSUE] vim arbitrary code execution via modeline voidlinux-github
  2019-06-04 23:40 ` voidlinux-github
  2019-06-05  0:51 ` voidlinux-github
@ 2019-06-05  7:39 ` voidlinux-github
  2019-06-05  7:58 ` [ISSUE] [CLOSED] " voidlinux-github
  3 siblings, 0 replies; 5+ messages in thread
From: voidlinux-github @ 2019-06-05  7:39 UTC (permalink / raw)
  To: ml

[-- Attachment #1: Type: text/plain, Size: 163 bytes --]

New comment by fosslinux on void-packages repository

https://github.com/void-linux/void-packages/issues/12152#issuecomment-498973941
Comment:
 #12154 closes this

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [ISSUE] [CLOSED] vim arbitrary code execution via modeline
  2019-06-04 23:16 [ISSUE] vim arbitrary code execution via modeline voidlinux-github
                   ` (2 preceding siblings ...)
  2019-06-05  7:39 ` voidlinux-github
@ 2019-06-05  7:58 ` voidlinux-github
  3 siblings, 0 replies; 5+ messages in thread
From: voidlinux-github @ 2019-06-05  7:58 UTC (permalink / raw)
  To: ml

[-- Attachment #1: Type: text/plain, Size: 282 bytes --]

Closed issue by congdanhqx on void-packages repository

https://github.com/void-linux/void-packages/issues/12152
Description: See https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md

neovim is also effected by this vulnerable but it's fixed in 0.3.7

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2019-06-05  7:58 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-06-04 23:16 [ISSUE] vim arbitrary code execution via modeline voidlinux-github
2019-06-04 23:40 ` voidlinux-github
2019-06-05  0:51 ` voidlinux-github
2019-06-05  7:39 ` voidlinux-github
2019-06-05  7:58 ` [ISSUE] [CLOSED] " voidlinux-github

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).