[slime-devel] Re: [PATCH] Bind *read-eval* in slime-version-string
Zach Beane
xach at xach.com
Mon Apr 21 10:23:30 UTC 2008
Madhu <enometh at meer.net> writes:
> Besides, not only is it not complicating things, it is The Right Thing
> To Do.
I don't think you should stop there. There is a dangerous file named
swank.lisp that is loaded by the lisp and slime.el is loaded by
emacs. An attacker thwarted by your ChangeLog fix could still modify
any of those files and take over your computer when you start slime!
Zach
More information about the slime-devel
mailing list