fixed in debian as well
Posted Jan 23, 2003 20:11 UTC (Thu) by
erich (subscriber, #7127)
Parent article:
vim - modeline vulnerability
I remember seeing this fix in Debian...
Maybe only in unstable though:
vim (6.1.263-1) unstable; urgency=low
[...]
* debian/runtime/vimrc: added 'set nomodeline' to address potential
security issue wherein malicious persons author files with hazardous
modelines, users unwittingly open said files and vim evaluates the
dangerous modelines
[...]
-- Luca Filipozzi <lfilipoz@debian.org> Tue, 26 Nov 2002 09:46:26 -0800
So Debian unstable has modlines disabled by default. I don't enable them for emails i reply to.
(
Log in to post comments)