Vulnerability Development mailing list archives

Re: sudo segfaults on large buffer


From: Ron DuFresne <dufresne () winternet com>
Date: Fri, 18 Jan 2002 07:27:31 -0600 (CST)


Date: Mon, 14 Jan 2002 07:44:02 -0700
From: Todd C. Miller <Todd.Miller () courtesan com>
To: sudo-announce () courtesan com
Subject: Sudo version 1.6.4 now available

Sudo version 1.6.4 is now available (ftp sites listed at the end).

There are some thing I had promised for the next release that are
not in 1.6.4 due to the large changes in the parser that these
changes require to work properly.  Nonetheless this release does
fix the majority of problems in the sudo bugs database and adds
features a number of people have asked for.  I hope to make more
frequent releases in the near future (it has been quite a while
since 1.6.3 was originally released).


On Fri, 18 Jan 2002, s1gnal_9  wrote:

Not really able to get more details, it gdb chokes while debugging...

I'm not even sure if this is known...

Tested on RH7.0 box.
Sudo version 1.6.3

sh-2.04# sudo -s `perl -e 'print("A"x4554)'`
Segmentation fault
-- 
_______________________________________________
Get your free email from http://sunos.com
Powered by Instant Portal


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"Cutting the space budget really restores my faith in humanity.  It
eliminates dreams, goals, and ideals and lets us get straight to the
business of hate, debauchery, and self-annihilation." -- Johnny Hart
        ***testing, only testing, and damn good at it too!***

OK, so you're a Ph.D.  Just don't touch anything.


Current thread: