An untrusted code execution
problem in Chicken Scheme: The interpreter loads a file called
".csirc" from the current directory on startup, without checking
whether it can be trusted.
Versions 4.8.2 after c6750af99ada7fa4815ee834e4e705bcfac9c137
are unaffected, as will 4.8.3 and later. The first stable release
to include a fix will be 4.9.0.
For the upstream advisory info see
http://lists.nongnu.org/archive/html/chicken-announce/2013-03/msg00002.html
and (important!) the errata:
http://lists.nongnu.org/archive/html/chicken-announce/2013-03/msg00003.html
Cheers,
Peter Bex
--
http://www.more-magic.net
//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information