Full Disclosure mailing list archives

Re: Buffer overflow in qmail-qmtpd, yet still qmail much better than windows


From: Daniel <deadbeat () sdf lonestar org>
Date: Wed, 3 Mar 2004 16:15:47 +0000 (UTC)


sooooooooooo close, i reckon you shuold get some that prize fund for
finding it though ;)

regards,
deadbeat

On Wed, 3 Mar 2004, Georgi Guninski wrote:

--------------------------------------------------
[joro@sivokote tmp]$ ./qma-qmtpd.pl
qmail-qmtpd buffer overflow. Copyright Georgi Guninski
Cannot be used in vulnerability databases and similar stuff

<in another terminal>
ps awx
2080 pts/9    S      0:00 /var/qmail/bin/qmail-qmtpd
gdb attach 2080
cont
<in first terminal hit enter>

Program received signal SIGSEGV, Segmentation fault.
0x0804b096 in alarm ()
--------------------------------------------------

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: