Vulnerability Development mailing list archives

Re: New bugs discovered!


From: Cabezon Aurélien <aurelien.cabezon () isecurelabs com>
Date: Mon, 19 Nov 2001 17:21:38 +0100



| > GOBBLES security is happy to announce the discovery of multiple bugs in
| > /bin/gzip, which can be exploited remotely with a bit of creativity.
| > Attached is our advisory on the matter.
| >
| > Enjoy the knowledge and remember to use it responsible.
| >
| > The GOBBLES Team
| > www.bugtraq.org
|

Tested on Linux redhat 7.2 [Roswell] 2.4.7-2
gzip 1.3

[root@r2d2 /]# gzip `perl -e 'print "A" x 2048'`
AAAAAAA[snipped] AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA: File name too long

It does not work anymore.

---
Cabezon Aurélien
http://www.iSecureLabs.com


Current thread: