Re: [POLL] Bug of Feature? Attack vector via deceiving link abbrevs (was: [ANN] Emergency bugfix release: Org mode 9.7.5)

2024-06-28 Thread Steven Allen
Ihor Radchenko writes: > Ihor Radchenko writes: > >> I just released Org mode 9.7.5 that fixes a critical vulnerability. >> The release is coordinated with emergency Emacs 29.4 release. > > This one is another potential issue (or a feature) we have found while > discussing the main

[POLL] Bug of Feature? Attack vector via deceiving link abbrevs (was: [ANN] Emergency bugfix release: Org mode 9.7.5)

2024-06-28 Thread Ihor Radchenko
Ihor Radchenko writes: > I just released Org mode 9.7.5 that fixes a critical vulnerability. > The release is coordinated with emergency Emacs 29.4 release. This one is another potential issue (or a feature) we have found while discussing the main vulnerability. Currently, one can create an

[POLL] We plan to remove #+LINK: ...%(my-function) placeholder from link abbreviation spec (was: [ANN] Emergency bugfix release: Org mode 9.7.5)

2024-06-28 Thread Ihor Radchenko
Dear all, > I just released Org mode 9.7.5 that fixes a critical vulnerability. > The release is coordinated with emergency Emacs 29.4 release. > ... > The vulnerability involves arbitrary Shell code evaluation... In a view of the recent vulnerability, we are considering to remove the offending

Assigned: CVE-2024-39331 (was: [ANN] Emergency bugfix release: Org mode 9.7.5)

2024-06-24 Thread Ihor Radchenko
Ihor Radchenko writes: > emacs-orgm...@city17.xyz writes: > >> Will a CVE be released? > > Should be, I think. > If nobody reports it independently by tomorrow, I will look into how to > request a CVE number myself. https://www.cve.org/CVERecord?id=CVE-2024-39331 -- Ihor Radchenko //

Re: [ANN] Emergency bugfix release: Org mode 9.7.5

2024-06-24 Thread Bastien Guerry
Ihor Radchenko writes: > I just released Org mode 9.7.5 that fixes a critical vulnerability. > The release is coordinated with emergency Emacs 29.4 release. Thank you a lot for your diligent and careful work on this! -- Bastien Guerry

Re: [ANN] Emergency bugfix release: Org mode 9.7.5

2024-06-22 Thread Steven Allen
Greg Troxel writes: > (Thanks for fixing and your efforts on org. I've been an org user since > at least July of 2010.) > > Just to be clear, is this the commit that needs applying to emacs > sources, 29.3, 28.x, and so on? Yes, that's the correct commit. > It seems so, but I would rather not

Re: [ANN] Emergency bugfix release: Org mode 9.7.5

2024-06-22 Thread Greg Troxel
(Thanks for fixing and your efforts on org. I've been an org user since at least July of 2010.) Just to be clear, is this the commit that needs applying to emacs sources, 29.3, 28.x, and so on? It seems so, but I would rather not guess. I'm asking on behalf of pkgsrc, where I am managing the

Re: [ANN] Emergency bugfix release: Org mode 9.7.5

2024-06-22 Thread Ihor Radchenko
emacs-orgm...@city17.xyz writes: > Will a CVE be released? Should be, I think. If nobody reports it independently by tomorrow, I will look into how to request a CVE number myself. > ... I am interested if there are mitigating factors > such as using `emacs -nw` (without GUI), thus no possible

Re: [ANN] Emergency bugfix release: Org mode 9.7.5

2024-06-22 Thread emacs-orgmode
Ihor Radchenko writes: I just released Org mode 9.7.5 that fixes a critical vulnerability. The release is coordinated with emergency Emacs 29.4 release. Thanks for the release and the anouncement. Will a CVE be released? I am interested if there are mitigating factors such as using `emacs

Re: [ANN] Emergency bugfix release: Org mode 9.7.5

2024-06-22 Thread Ihor Radchenko
Ihor Radchenko writes: > Please upgrade your Org mode *and* Emacs ASAP. *Org mode or Emacs. The fix is purely in Org code, so upgrading Emacs is only needed when you want to use built-in Org mode. Otherwise, it is enough to upgrade Org mode via ELPA (the tarball will be available soon, after

[ANN] Emergency bugfix release: Org mode 9.7.5

2024-06-22 Thread Ihor Radchenko
Dear all, I just released Org mode 9.7.5 that fixes a critical vulnerability. The release is coordinated with emergency Emacs 29.4 release. Please upgrade your Org mode *and* Emacs ASAP. The vulnerability involves arbitrary Shell code evaluation when previewing attachments in Emacs MUA