Vulnerability Development mailing list archives

Re: Buffer overflow in awk


From: Jason Stover <jason () csc parkland cc il us>
Date: Fri, 15 Mar 2002 11:28:40 -0600 (CST)

Verified this on: 

  SuSE 7.2 - awk Ver. 3.0.6
  SuSE 7.0 - awk Ver. 3.0.5
  SuSE 6.4 - awk Ver. 3.0.4
  SuSE 6.3 - awk Ver. 3.0.4 *Unsupported SuSE version*
  Slack 7.1 - awk Ver. 3.0.4

  All needed a length of 8177 



On 15 Mar 2002, keoki wrote:


A buffer overflow exist in awk(named awk on most 
systems, but actualy is gawk/GNU awk) when calling 
the -f option, to include an awk script, and supplying a 
filename with a buffer length of 1022 and up. 

  [ .. ]

This was tested on FreeBSD platform(fbsd 4.0 && 
4.4) against awk(which is actually gnu awk) versions 
3.0.6 && 3.0.4 



Current thread: