Vulnerability Development mailing list archives

Re: core dump on mingetty and getty


From: "Nelson Sampaio Araujo Junior" <nelson () lunenetworks com br>
Date: Mon, 3 Dec 2001 17:43:22 -0200

I've detected it under Mandrake 8.1.

Thus, this attack was not able to currupt EIP register, what is a good
signal. It screws up EAX and EDX registers.

Regards,
Nelson Junior
nelson () lunenetworks com br
nelson () LUNE com br

----- Original Message -----
From: "Ryan Yagatich" <ryany () procyon pantek com>
Cc: <vuln-dev () security-focus com>
Sent: Monday, December 03, 2001 5:21 PM
Subject: Re: core dump on mingetty and getty


$ cd ~
$ /sbin/mingetty `perl -e 'print "A" x 275'`
$ /sbin/mingetty `perl -e 'print "A" x 276'`
Segmentation fault
$ uname -a
Linux frodo.devel.lab 2.4.7-10 #1 ...





Current thread: