Bugtraq mailing list archives

Re: [ Hackerslab bug_paper ] Linux dump buffer overflow


From: venglin () FREEBSD LUBLIN PL (Przemyslaw Frasunek)
Date: Thu, 2 Mar 2000 06:50:07 +0100


On 01-Mar-2000 Derek Callaway wrote:
(gdb) #0  getenv (name=0x40111a70 "") at ../sysdeps/generic/getenv.c:88
From this gdb session, it appears that there _could_ be a problem with
the way that glibc's time functions behave.

No. getenv() fails because *envp, argc, **argv are AFTER pathname[]
buffer and gets overwritten.

Of course, it is still exploitable.

--
* Fido: 2:480/124 ** WWW: http://www.freebsd.lublin.pl ** NIC-HDL: PMF9-RIPE *
* Inet: venglin () freebsd lublin pl ** PGP: D48684904685DF43  EA93AFA13BE170BF *



Current thread: