Vulnerability Development mailing list archives

Re: Possible syslogd DoS ?


From: H D Moore <hdm () secureaustin com>
Date: Fri, 5 Oct 2001 11:28:39 -0500

Are you sure tha /dev/urandom will never return a string with %[snpfdn] etc? 
Your exploit may be exploitable ;)

On Friday 05 October 2001 12:19 am, Petr Baudis wrote:

  for(;;)
  {
    fgets(buffer, sizeof(buffer), fp);
    syslog(0, buffer);
  }

Fix: syslog(0, "%s", buffer);

-- 
H D Moore
http://www.digitaldefense.net - work
http://www.digitaloffense.net - play


Current thread: