Asheesh Laroia <[EMAIL PROTECTED]> writes:

> Version: 0.11.1-1.2
>
> It's easy to enable JavaScript support for elinks, and basic
> JS/ECMAScript support would really go a long way given all of the dumb
> pages on the web that require it (for things like following links or
> submitting forms).

ECMAScript support in ELinks 0.11.1 has several bugs that can
cause SIGSEGV.  Some of them may be exploitable for running
arbitrary code.  (If you can prove otherwise, please add your
reasoning to the upstream bugs.)  In my opinion, Debian should
not enable ECMAScript in this version.

http://bugzilla.elinks.cz/show_bug.cgi?id=755
http://bugzilla.elinks.cz/show_bug.cgi?id=846
http://bugzilla.elinks.cz/show_bug.cgi?id=870
http://bugzilla.elinks.cz/show_bug.cgi?id=956
http://elinks.cz/release.html

Please consider using ELinks 0.12 snapshots instead, because all
known ECMAScript crashes (but not hangs) have been fixed there.
ELinks 0.12.0 has not yet been released because 0.12.GIT still
has some regressions from 0.11.3.

Attachment: pgpCXT0RS7231.pgp
Description: PGP signature

Reply via email to