Vulnerability Development mailing list archives
Re: TCSH problems?
From: Flux9 <flux9 () 101freeway net>
Date: Wed, 06 Jun 2001 08:27:46 +0000
Alex wrote:
After some ktracing, and code auditing by myself and a colleague, we believe the problem *may* infact be in libc's setenv() and getenv() functions. We were able to duplicate the bug on various platforms, mostly causing signal 6s and dumping cores. Feedback would be appreciatedsetenv HOME `perl -e 'print "/" x 10000'`^ Length varies from 1024-10000 for effectiveness on diffrent OSes. -Alex
check this out: (slackware 7.1, tcsh 6.09) read(3, "/////////////////////////////////" ..., 1024) = 784 After looking at strace results, it appears as the excess char's blow out that buffer (1024 bytes), but the actual abort results from massive forking of children after this buffer is blown, not the buffer itself. who knows.
Current thread:
- nonsuid overflows... still at risk? KF (Jun 05)
- TCSH problems? Alex (Jun 06)
- Re: TCSH problems? Alex (Jun 06)
- Re: TCSH problems? Alex (Jun 06)
- Re: TCSH problems? Mike Duncan (Jun 06)
- Re: TCSH problems? Flux9 (Jun 06)
- Re: TCSH problems? KF (Jun 06)
- Re: TCSH problems? KF (Jun 06)
- Re: TCSH problems? Guezou Philippe (Jun 06)
- Re: TCSH problems? Alex (Jun 06)
- TCSH problems? Alex (Jun 06)
- Re: TCSH problems? Kevin J. Menard, Jr. (Jun 06)
- Re: TCSH problems? Flux9 (Jun 06)
- Re: TCSH problems? Sven van ´t Veer (Jun 06)
- Re: TCSH problems? Edsel Adap (Jun 06)
- Re: TCSH problems? Felix Kronlage (Jun 06)
- Re: TCSH problems? Andreas Forsgren (Jun 06)
- Re: TCSH problems? Branko Ivanovic (Jun 06)