[slime-devel] Re: [PATCH] Bind *read-eval* in slime-version-string
xach at xach.com
Tue Apr 22 13:36:57 UTC 2008
Madhu <enometh at meer.net> writes:
> * Zach Beane <m37ierik0t.fsf at unnamed.xach.com> :
> Wrote on Mon, 21 Apr 2008 06:23:30 -0400:
> |> Besides, not only is it not complicating things, it is The Right Thing
> |> To Do.
> | I don't think you should stop there. There is a dangerous file named
> | swank.lisp that is loaded by the lisp and slime.el is loaded by
> | emacs. An attacker thwarted by your ChangeLog fix could still modify
> | any of those files and take over your computer when you start slime!
> See <URL:http://permalink.gmane.org/gmane.lisp.slime.devel/7300>
> upthread in this thread where I explained why swank.lisp and slime.el
> are not a problem.
I saw it. Count me as one of the unpersuaded.
More information about the slime-devel