Vulnerability Development mailing list archives

Re: sshd ioctl bug?


From: Pavel Kankovsky <peak () argo troja mff cuni cz>
Date: Fri, 22 Feb 2002 11:18:08 +0100 (MET)

On Thu, 21 Feb 2002, Gabriel A. Maggiotti wrote:

[root@pluto openssh-2.9p2]# perl -e 'printf "A"x16384' >a
[root@pluto openssh-2.9p2]# telnet pluto 22 <a
Trying 192.168.0.2...
Connected to pluto.net.
Escape character is '^]'.
pluto.net: Inappropriate ioctl for device
SSH-1.99-OpenSSH_2.9p2
Protocol mismatch.
Connection closed by foreign host.

Is this a real security problem?

Maybe. But it's telnet's problem, not sshd's!

<rant> Yes, I know the distiction between client errors and server errors
can be confusing but it would be nice if people sending reports to this
list bothered to use their wetware to (at least) determine whose problem
they report before they send it. </rant>

--Pavel Kankovsky aka Peak  [ Boycott Microsoft--http://www.vcnet.com/bms ]
"Resistance is futile. Open your source code and prepare for assimilation."


Current thread: