Vulnerability Development mailing list archives

Re: Bash Blues.


From: Dack <bugtraq42 () hotpop com>
Date: Thu, 13 Feb 2003 16:37:17 -0800

On Thu, Feb 13, 2003 at 05:08:23PM +0000, Andrew Walkingshaw wrote:
On Thu, Feb 13, 2003 at 02:26:51PM +0000, uk2sec () oakey no-ip com wrote:
[ Moderator:  Post Edited Accordingly ]

uk2sec /bin/bash Advisory

By sending a perl request on the GNU bash terminal we can cause a 
Segmentation Fault.

Work done was based on:
    GNU bash, version 2.05a.0(1)-release (i686-pc-linux-gnu)
    (Redhat 7.3)


I can't reproduce this.

:; uname -a
Linux shimari 2.4.18-17.8.0bigmem #1 SMP Tue Oct 8 12:07:38 EDT 2002 i686 i686 i386 GNU/Linux

I can.  Gentoo 1.2.

$ uname -a                                                                                  
$ Linux dc.dcnet 2.4.19-gentoo-r10 #1 Sun Dec 15 15:04:22 PST 2002 i686 Celeron (Mendocino) 
+GenuineIntel GNU/Linux

It's not the same amount though.  2340 is the right amount for me.

GNU bash, version 2.05a.0(1)-release (i686-pc-linux-gnu)


Current thread: