From xemacs-m  Thu Sep 25 09:09:44 1997
Received: from kiki.icd.teradyne.com (kiki.icd.teradyne.com [131.101.10.126])
	by xemacs.org (8.8.5/8.8.5) with ESMTP id JAA18287
	for <xemacs-beta@xemacs.org>; Thu, 25 Sep 1997 09:09:43 -0500 (CDT)
Received: from localhost.icd.teradyne.com (localhost.icd.teradyne.com)
	by ICD.Teradyne.COM (8.8.5/8.8.5) with SMTP id KAA11870
	for <xemacs-beta@xemacs.org>; Thu, 25 Sep 1997 10:07:54 -0400 (EDT)
Received: from honeydew.icd.teradyne.com by honeydew.icd.teradyne.com (SMI-8.6/SMI-SVR4)
	id KAA07717; Thu, 25 Sep 1997 10:09:13 -0400
Message-Id: <199709251409.KAA07717@honeydew.icd.teradyne.com>
X-Mailer: exmh version 2.0zeta 7/24/97
To: xemacs-beta@xemacs.org
Subject: Re: Fatal serious (security) flaw in XEmacs 19.16/20.3 
In-reply-to: steve's message of 24 Sep 1997 23:08:30 -0700.
	     <m2zpp22ae9.fsf@altair.xemacs.org> 
From: acs@acm.org
X-Attribution: Vin
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Date: Thu, 25 Sep 1997 10:09:13 -0400
Sender: shelton@ICD.Teradyne.COM


steve@xemacs.org said:
> Please evaluate this function (in a separate invocation if you are
> reading mail in XEmacs) and report back if you *do not* see an error
> message or check to see what your system #defines MAXNAMLEN to.

> (directory-files "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
> aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
> aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
> aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa")


Here's what I see from "19.16 \"Queens\" XEmacs Lucid", built on Solaris 
2.4, but running on 2.5.1:

Opening directory: file name too long, /u/shelton/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa

No fatal error, so it appears to work for me here.

vin

