[ubuntu/oneiric-security] emacs23 23.3+1-1ubuntu4.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Thu Sep 27 17:08:15 UTC 2012


emacs23 (23.3+1-1ubuntu4.1) oneiric-security; urgency=low

  * SECURITY UPDATE: untrusted search path vulnerability
    - debian/patches/CVE-2012-0035.patch: add new option and use it in
      lisp/cedet/ede/auto.el, lisp/cedet/ede.el, lisp/cedet/ede/simple.el.
    - CVE-2012-0035
  * SECURITY UPDATE: arbitrary lisp code execution via crafted file
    - debian/patches/CVE-2012-3479.patch: ignore eval: forms that are not
      known to be safe if enable-local-variables is set to :safe in
      lisp/files.el.
    - CVE-2012-3479

Date: 2012-09-21 18:55:12.848684+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/oneiric/+source/emacs23/23.3+1-1ubuntu4.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Oneiric-changes mailing list