Re: [E-devel] Terminology 1.3.1

2018-12-17 Thread Ben N
CVE-2018-20167 has now been assigned to this vulnerability. Package maintainers for major distros have been notified. On Mon, Dec 17, 2018 at 3:36 AM Ross Vandegrift wrote: > On Sun, Dec 16, 2018 at 02:36:53PM +0100, Boris Faure wrote: > > The issue is a Remote Code Execution vulnerability

Re: [E-devel] Terminology 1.3.1

2018-12-16 Thread Ross Vandegrift
On Sun, Dec 16, 2018 at 02:36:53PM +0100, Boris Faure wrote: > The issue is a Remote Code Execution vulnerability caused by > Terminology's special escape codes. Those can already be disabled in > the Settings panel. Hi Ben - you mentioned getting a CVE in the phab report. Has that been

[E-devel] Terminology 1.3.1

2018-12-16 Thread Boris Faure
Hello fellow Terminology enthusiasts! I was made aware of a security issue in Terminology this morning ( https://phab.enlightenment.org/T7504 ). I acknowledged the issue and worked on a fix that is now provided in Terminology 1.3.1. The issue is a Remote Code Execution vulnerability caused by