Vulnerability Development mailing list archives

Re: traceroute-4.4BSD (slack) heap overflow


From: Frank de Lange <frank () UNTERNET ORG>
Date: Tue, 9 Jan 2001 14:39:34 +0100

On Mon, Jan 08, 2001 at 04:30:01PM +0000, Dale Thatcher wrote:
On Mon, Jan 08, 2001 at 11:54:41AM +0100, Olaf Kirch wrote:
 c. The RESOLV_HOST_CONF variable is *not* used to specifiy
    a replacment for /etc/hosts, but for /etc/host.conf, which
    configures the resolver. Apart from that, it's been quite a
    while since the resolver library honored this variable in
    setuid programs.

I just tried this on Debian unstable (libc 2.2-9) and read my /etc/shadow

Whoops...

- Dale

Same here, libc-2.2 on a homebrew GNU/Linux installation...

Oops indeed...

Frank

--
  WWWWW      _______________________
 ## o o\    /     Frank de Lange     \
 }#   \|   /                          \
  ##---# _/     <Hacker for Hire>      \
   ####   \      +31-320-252965        /
           \    frank () unternet org    /
            -------------------------
 [ "Omnis enim res, quae dando non deficit, dum habetur
    et non datur, nondum habetur, quomodo habenda est."  ]


Current thread: