Vulnerability Development mailing list archives

Re: sadc Segmentation Fault


From: KF <dotslash () snosoft com>
Date: Fri, 07 Dec 2001 12:56:46 -0500

I am sorry let me correct myself... 5.0.5 core dumps 5.0.6 does not. 
here is the letter I sent smackenz on monday . 

          Re: core dump on mingetty and getty
      Date: 
          Mon, 03 Dec 2001 18:14:47 -0500
     From: 
          KF <dotslash () snosoft com>
       To: 
          smackenz <smackenz () brad ac uk>
 References: 
          1 , 2 , 3




I didn't have it on my linux box... but SCO does have it ... 5.0.6 was
not vuln  5.0.5 IS. 

SCO_SV unixdev 3.2 5.0.5 i386
$ /usr/lib/sa/sadc  `perl -e 'print "A" x 9000'`
Memory fault(coredump)

root () sco checkfree com #uname -a
SCO_SV sco 3.2 5.0.6 i386

root () sco checkfree com #/usr/lib/sa/sadc  `perl -e 'print "A" x 9000'`
sadc: Filename too long
-KF




Andrew Sharpe @ caldera.com wrote:

I can't duplicate this. How many A's did you use? And have you applied
5.0.6a? Please supply more data...

        Thanks,

        Andrew

On Fri, Dec 07, 2001 at 11:27:17AM -0500, KF wrote:
OpenServer 5.0.6 sadc also causes core dump...
-KF

Following this as user 'smackenz' I carried out the following commands:
[smackenz@mainframe smackenz]$ /usr/lib/sa/sadc `perl -e 'print "A" x 200'`
[smackenz@mainframe smackenz]$ /usr/lib/sa/sadc `perl -e 'print "A" x 210'`
[smackenz@mainframe smackenz]$ /usr/lib/sa/sadc `perl -e 'print "A" x 220'`
[smackenz@mainframe smackenz]$ /usr/lib/sa/sadc `perl -e 'print "A" x 230'`
[smackenz@mainframe smackenz]$ /usr/lib/sa/sadc `perl -e 'print "A" x 240'`
[smackenz@mainframe smackenz]$ /usr/lib/sa/sadc `perl -e 'print "A" x 250'`
[smackenz@mainframe smackenz]$ /usr/lib/sa/sadc `perl -e 'print "A" x 260'`
Cannot open
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
File name too long
[smackenz@mainframe smackenz]$ /usr/lib/sa/sadc `perl -e 'print "A" x 270'`
Cannot open
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
File name too long
etc.... until
[smackenz@mainframe smackenz]$ /usr/lib/sa/sadc `perl -e 'print "A" x 290'`
Segmentation fault (core dumped)
-------------------------------------------------------
Later
Scott.



Current thread: