Bugtraq mailing list archives
Re: More telnet Daemon Fun
From: sopwith () redhat com (Elliot Lee)
Date: Wed, 3 Dec 1997 01:11:52 -0500
On Mon, 1 Dec 1997, Aaron Campbell wrote:
Thanks to Jason Parsons <root () saffroncs com> for pointing this one out:
[telnet bug snipped]
Segmentation fault (core dumped) [fx@somehost fx]$ ls -l core -rw------- 1 fx nnh 315392 Dec 1 21:51 core [fx@somehost fx]$ That's 256 characters up there, BTW. Also, note we're setting the DISPLAY variable this time, not TERM.
On Red Hat Linux 5.0, which uses glibc and a newer netkit, if I follow the above procedure and telnet to either localhost, a Solaris box, or a 4.2 box, it just hangs when I telnet with the long $DISPLAY, and I tire of waiting and kill the telnet client. If I telnet from a RHL 4.2 box to anything, it does the segfault. This seems to indicate that there is a buffer overflow in old(er) versions of the telnet client. No joy, -- Elliot Seen on comp.os.linux.development.system: "I WOULD LIKE TO INSERT SOME SYSTEM CALL IN LINUX. BUT I DON'T KNOW WHERE IS THE KERNEL SOURCE AND HOW TO COMPILE THE KERNEL PLEASE HELP ME! FROM censored -MY EMAIL DOESN'T WORK."
Current thread:
- Possible Solaris 2.6 hole at(1M), (continued)
- Possible Solaris 2.6 hole at(1M) sp00n (Dec 02)
- Re: Possible Solaris 2.6 hole at(1M) Casper Dik (Dec 04)
- Re: an detailed explaination why land attack works? Bill Paul (Dec 03)
- Fw: Insufficient allocations in net/unix/garbage.c (fwd) Phillip R. Jaenke (Dec 03)
- Re: Fw: Insufficient allocations in net/unix/garbage.c (fwd) Alan Cox (Dec 04)
- Sun Security Bulletin #00159 (fwd) Howie (Dec 03)
- Sun Security Bulletin #00160 (fwd) Howie (Dec 03)
- Q165005: Windows NT Slows Down Due to Land Attack Aleph One (Dec 04)
- Q177539: Windows 95 Stops Responding Because of Land Attack Aleph One (Dec 04)
- More telnet Daemon Fun Aaron Campbell (Dec 01)
- Re: More telnet Daemon Fun Elliot Lee (Dec 02)
- tcsh/Solaris (Re: More telnet Daemon Fun) Peter Radcliffe (Dec 03)
- scoterm exploit Aleph One (Dec 04)
- Re: Linux inetd.. Alan Cox (Dec 02)
- Re: Linux inetd.. Darren Reed (Dec 02)
- Re: Linux inetd.. Darren Reed (Dec 02)