Bugtraq mailing list archives

Re: $HOME buffer overflow in SunOS 5.8 x86


From: Kris Kennaway <kris () obsecurity org>
Date: Wed, 6 Jun 2001 09:44:13 -0700

On Tue, Jun 05, 2001 at 01:54:11PM -0500, Gunnar Wolf wrote:

digital> uname -a
OSF1 digital V4.0 564.32 alpha
digital> setenv HOME `perl -e 'print "a"x1100'`
Received disconnect: Command terminated on signal 6.

There was a bug in tcsh which did this, which I reported about 6
months ago and was fixed by Christos.  Not a security vulnerability,
of course, unless your shell is already setugid ;-)

Kris

Attachment: _bin
Description:


Current thread: