Vulnerability Development mailing list archives

Re: Buffer overflow in Python code


From: Florian Weimer <Florian.Weimer () RUS Uni-Stuttgart DE>
Date: 26 Nov 2001 23:54:07 +0100

Chris Ess <azarin () tokimi net> writes:

Using the supplied script, I did achieve a segfault during the traceback
with Python 2.1.  However, I'm hardpressed to figure out how one would
exploit this...  After all, the Python binary is rarely SUID or SGID.  (I
know it's not on my system.)

It's perhaps an issue with applications featuring embedded Python,
like Zope.

-- 
Florian Weimer                    Florian.Weimer () RUS Uni-Stuttgart DE
University of Stuttgart           http://cert.uni-stuttgart.de/
RUS-CERT                          +49-711-685-5973/fax +49-711-685-5898


Current thread: