Full Disclosure mailing list archives

Re: Kmail <= 1.9.1 (latest) DOS


From: "the.soylent" <the.soylent () gmail com>
Date: Mon, 09 Oct 2006 21:33:36 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


SecuriTeam Expert schrieb:
What drivers do you use for X ? (my guess nvidia).

yes, nvidia ;)
not only ff or gedit crash the x-server, also opening it with epiphany
(0.5.1-1ubuntu1) does the job ;)

ok, i tested a bit more around:
i open the link on a fresh installed & full patched ubuntu 6.06, 32 and
64 bit version..(also nvidia-graphic) same effect:

- -32bit-
Linux amd3800-64 2.6.15-27-amd64-generic
X:  7.0.0-0ubuntu45
gnome: 1:2.12.2.3
nvidia-kernel-common: 20051028+1

- -64bit-
Linux amd3800 2.6.15-27-k7
gnome, x, .. : same as above

firefox -> crash
gedit -> crash
epiphany -> crash


interesting part:
when the x server previously runs on tty7, it runs after crash at tty8
and vice versa.
at the "crashed tty" is displayed the following (64bit):

*** glibc detected *** free(): invalid next size (normal):
0x0000000001094d50 *** glibc detected *** double free or corruption
(!prev) 0x00000000010661e0 ***

same messages on the 32bit-system (with shorter memory-addresses)

tested it also on a debian-sarge-system (kde+gnome) and pleased someone
with gentoo (fluxbox) to test it: no effect
maybe ubuntu-specific?

hope this helps,
/soylent

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFFKqQPY86qEhC92cgRAvIOAJ44GQKNQbfIEdLoWZtw654U6JAacwCeOpb5
gUv/8WCUEJ+ZShG6gdY/psk=
=KT1N
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: