Vulnerability Development mailing list archives

Re: Can anyone verify a core dump on /sbin/mingetty


From: jon schatz <jon () divisionbyzero com>
Date: 03 Dec 2001 12:14:28 -0800

On Mon, 2001-12-03 at 11:57, Scott Mackenzie wrote:
Cheers Jon, by the program didn't dump core because you don't have write 
access to sbin.  As it turns out 7.2 is vulnrable.

not true on these machines. i tried as root:

root@dev:/home/jon whoami
root
root@dev:/home/jon /sbin/mingetty `perl -e 'print "A"x9000'`
Segmentation fault

still no core. here's some sys info:

root@dev:/home/jon rpm -q mingetty
mingetty-0.9.4-18
root@dev:/home/jon rpm -q glibc
glibc-2.2.4-19
root@dev:/home/jon uname -mrspv
Linux 2.4.15-pre8 #1 Sat Nov 24 13:08:16 PST 2001 i686 unknown

-jon

-- 
jon () divisionbyzero com || www.divisionbyzero.com
gpg key: www.divisionbyzero.com/pubkey.asc
think i have a virus?: www.divisionbyzero.com/pgp.html
"You are in a twisty little maze of Sendmail rules, all confusing." 

Attachment: _bin
Description:


Current thread: