LWN.net Logo

fixed in debian as well

fixed in debian as well

Posted Jan 23, 2003 20:11 UTC (Thu) by erich (subscriber, #7127)
Parent article: vim - modeline vulnerability

I remember seeing this fix in Debian...
Maybe only in unstable though:

vim (6.1.263-1) unstable; urgency=low

  [...]
  * debian/runtime/vimrc: added 'set nomodeline' to address potential
    security issue wherein malicious persons author files with hazardous
    modelines, users unwittingly open said files and vim evaluates the
    dangerous modelines
  [...]

 -- Luca Filipozzi <lfilipoz@debian.org>  Tue, 26 Nov 2002 09:46:26 -0800
So Debian unstable has modlines disabled by default. I don't enable them for emails i reply to.


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds