Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Order Openwall GNU/*/Linux 2.0 on a CD with delivery worldwide
[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Wed, 14 May 2008 18:02:32 +0200
From: Sven Joachim <svenjoac@....de>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution

On 2008-05-14 16:43 +0200, Nico Golde wrote:

> Hi Sven,
> * Sven Joachim <svenjoac-Mmb7MZpHnFY@...lic.gmane.org> [2008-05-14 16:12]:
>> On 2008-05-14 15:27 +0200, Nico Golde wrote:
>> > As I am a vim user I might have done something wrong too, 
>> > not sure. What I did after installing emacs:
>> > cat >> ~/.emacs << EOF
>> > (global-font-lock-mode t)
>> > (seq font-lock-support-mode 'fast-lock-mode)
>> > EOF
>> 
>> Should read setq, not seq.  You will also need to load fast-lock
>> explicitly before that, since it's obsolete and not automatically
>> loaded anymore:
>
> Where is the difference? seq was from:
> http://lists.gnu.org/archive/html/emacs-devel/2008-05/msg00645.html

That was a typo.  AFAIK, there is no seq function in Emacs.

>> (message "Surprise, surprise!")
>
> Thanks, missed the (message...)
>
>> This string will be put in the echo area when you visit foobar.c.
>
> Confirmed, works now as expected, not confirmation dialog though.

I don't see a confirmation dialog either.

Sven

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux