Index: bug1.html =================================================================== --- bug1.html (revision 11600) +++ bug1.html (revision 11601) @@ -28,7 +28,7 @@ allows any configuration setting to be specified in a project file or a board file. This includes the above 5 items as well.

-An attacker may produce a project or a single board file in .pcb or .lht format +Thus an attacker may produce a project or a single board file in .pcb or .lht format that contains the above config settings, executing arbitrary code on the user's computer when pcb-rnd opens or saves the file or loads fonts or footprints or netlists.