Vulnerability Development mailing list archives

Re: character injecting on linux console


From: Robert van der Meulen <rvdm () wiretrip org>
Date: Sat, 8 Dec 2001 19:29:44 +0100


Quoting Michal Zalewski (lcamtuf () coredump cx):
readers etc do not expand certain sequences properly. I failed to find any
program that can be effectively exploited by issuing a very limited set of
commands (6c, ;something, etc), but probably if you search carefully
enough, you'll find something :>
I can remember an 'issue' with window maker and some mail
client-combination. Don't recall the exact exploit stuff or any more
details, though.

Greets,
        Robert

-- 
                              Linux Generation
   encrypted mail preferred. finger rvdm () debian org for my GnuPG/PGP key.
            Insanity is hereditary.  You get it from your kids.


Current thread: