oss-sec mailing list archives
CVE request for emacs possibly
From: Kurt Seifried <kseifried () redhat com>
Date: Tue, 30 Dec 2014 20:17:02 -0700
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774090 From: Vincent Lefevre <vincent () vinc17 net> To: 774090 () bugs debian org Subject: Re: emacs24: a left-click in Emacs sometimes modifies the PRIMARY selection Date: Mon, 29 Dec 2014 18:58:55 +0100 Control: tags -1 security On 2014-12-28 16:29:12 +0100, Vincent Lefevre wrote:
Note: This bug occurs very often and is very annoying, as one needs to reselect what was selected (sometimes hardly possible). Moreover the wrongly pasted text is similar to the correct text[*], meaning that if one doesn't pay attention, one gets a file with permanently incorrect data!
Grrr... That's also a security problem. Due to this bug, a paste with a middle click in a web browser can end up in pasting private data! And Javascript can provide the pasted text to the web site immediately (Facebook does that), before the user can notice the problem. -- Vincent Lefèvre <vincent () vinc17 net> - Web: <https://www.vinc17.net/> 100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/> Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon) -- Kurt Seifried -- Red Hat -- Product Security -- Cloud PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- CVE request for emacs possibly Kurt Seifried (Dec 30)