Vulnerability Development mailing list archives

Re: possible su local D.o.S


From: "Emre Yildirim" <emre () asper org>
Date: Thu, 13 Dec 2001 15:10:01 -0600 (CST)


On my RH 7.2 I tried this :

[hvc@condor hvc] $ su `perl -e 'print "A" x 100000000'`

I get something rather different

% su `perl -e 'print "A" x 100000000'`
zsh: fatal error: out of memory

After 5 seconds the shell just dies, I get a connection closed by remote host
(this is when I ssh into the box).  The system still functions though. 
After Ilog back in, the command is not in .zsh_history for some reason and I can't
recall it pushing the up arrow.


-- 
Emre Yildirim <emre () asper org>
GPG KeyID 0xF9E4A1D1 (pgpkeys.mit.edu)



Current thread: