4 ms·
I guess we have a winner for Editor Wars.
by Pmop 7y ago
I guess we have a winner for Editor Wars.
- NegativeLatency 7y agoEmacs has similar functionality https://www.gnu.org/software/emacs/manual/html_node/emacs/Specifying-File-Variables.html https://www.gnu.org/software/emacs/manual/html_node/emacs/Sp...
- Pmop 7y agoIs there any CVE on it published already? It'd be very funny if yes or if someone publishes one following Vim's.
- projektfu 7y agoYep. Search the text for "variable" https://www.cvedetails.com/vulnerability-list.php?vendor_id=72&product_id=741&version_id=0&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=0&cweid=0&order=1&trc=21&sha=001be71c19fab6171046f0b812da8d1378e05f02 https://www.cvedetails.com/vulnerability-list.php?vendor_id=...
- nonbirithm 7y agoThe default behavior on Emacs is to warn you that file-local variables can be unsafe and prompt you to execute them. However I developed the habit of mostly ignoring it since they're usually in my own files. https://www.gnu.org/software/emacs/manual/html_node/emacs/Safe-File-Variables.html https://www.gnu.org/software/emacs/manual/html_node/emacs/Sa...
- NikkiA 7y agoThe scary part for me (albeit that I'm an emacs user not really a vim user) here is that the modeline string is hidden from the victim in their vim window, so not only have they enabled the RCE they aren't aware of it. I'm not sure if emacs file-local variables can be exploited in the same way (they probably can but I'm just unaware of it)