Bugtraq mailing list archives

Re: Linux login buffer overflow


From: daveg () ESCAPE COM (Dave G.)
Date: Sun, 22 Dec 1996 16:46:18 -0500


After a quick look through, this doesnt look too dangerous.  I doubt someone
could get it to exec a shell.

Same reason why rlogin was unexploitable, main never returns, only exits.
However, it is still a potential problem, just not another return address
overwrite.

Dave G.
<daveg () escape com>
http://www.escape.com/~daveg



Current thread: