Vulnerability Development mailing list archives

Re: [Fwd: Help needed with bufferoverflow in cvs]


From: larry.jones () sdrc com (Larry Jones)
Date: Fri, 22 Feb 2002 10:17:10 -0500 (EST)

Turbo Fredriksson writes:

I was running the Debian GNU/Linux version 1.11.1p1-1, had the same
problem. Upgraded to '1.11.1p1-5', same problem.

No, you do *not* have the same problem.

diff -u -b -B 
-Caaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
 -r2.0.0.1 Makefile
cvs server: invalid context length argument

That's a legitimate error (-C takes an *integer* argument, which
"aaa..." is not).  The *problem* was that that used to cause CVS to
*crash*.  You're not getting the crash.

-Larry Jones

These findings suggest a logical course of action. -- Calvin


Current thread: