bug-gnu-emacs
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#44018: Don't consider play-sound-file to be a 'safe' function


From: Mattias Engdegård
Subject: bug#44018: Don't consider play-sound-file to be a 'safe' function
Date: Mon, 26 Oct 2020 17:51:37 +0100

reopen 44018
stop

[Stefan, I think you accidentally closed the bug when replying to 
44018-done@debbugs.gnu.org. I would probably have made the same mistake!]

26 okt. 2020 kl. 17.32 skrev Stefan Kangas <stefan@marxist.se>:

> FWIW, I agree with this change.  There have been many vulnerabilities
> in this area, for example in the Linux kernel drivers.  Who knows what
> else is out there.

Yes, and some of us have dealt with these things for decades.
My fav audio bug in Linux is the famous gstreamer NES emu exploit [1], which is 
a good example of what I tried to explain about attack surfaces and unknown 
dangers.

[1] 
https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit-compromising-linux-desktop.html






reply via email to

[Prev in Thread] Current Thread [Next in Thread]