Vulnerability Development mailing list archives
Re: Bash Blues.
From: Peter Pentchev <roam () ringlet net>
Date: Fri, 14 Feb 2003 10:24:13 +0200
On Thu, Feb 13, 2003 at 02:26:51PM +0000, uk2sec () oakey no-ip com wrote:
[ Moderator: Post Edited Accordingly ] uk2sec /bin/bash Advisory By sending a perl request on the GNU bash terminal we can cause a Segmentation Fault. Work done was based on: GNU bash, version 2.05a.0(1)-release (i686-pc-linux-gnu) (Redhat 7.3)
[snip]
Background: During some work, I noticed GNU bash could be crashed by sending a malformed perl request to the terminal. example: `perl -e 'print "*/*" x 3500'` <bash crashes>
I cannot reproduce this in bash-2.05b.0(1)-release on FreeBSD 4.7-STABLE. ISTR that some of the changes between 2.05a and 2.05b had something to do with globbing, but it is not immediately obvious from the 2.05b change log, unless this is part of the internal malloc() overhaul. Can you test this with bash-2.05b? G'luck, Peter -- Peter Pentchev roam () ringlet net roam () sbnd net roam () FreeBSD org PGP key: http://people.FreeBSD.org/~roam/roam.key.asc Key fingerprint FDBA FD79 C26F 3C51 C95E DF9E ED18 B68D 1619 4553 .siht ekil ti gnidaer eb d'uoy ,werbeH ni erew ecnetnes siht fI
Attachment:
_bin
Description:
Current thread:
- Re: Bash Blues., (continued)
- Re: Bash Blues. Dack (Feb 14)
- Re: Bash Blues. Roland Postle (Feb 14)
- glibc glob_filename() recurse call stack overflow (Re[2]: Bash Blues) 3APA3A (Feb 15)
- Re: glibc glob_filename() recurse call stack overflow (Re[2]: Bash Blues) Vladamir Shmirnov (Feb 15)
- Re: glibc glob_filename() recurse call stack overflow (Re[2]: Bash Blues) Roland Postle (Feb 16)
- Re: glibc glob_filename() recurse call stack overflow (Re[2]: Bash Blues) spacewalker (Feb 16)
- glibc glob_filename() recurse call stack overflow (Re[2]: Bash Blues) 3APA3A (Feb 15)
- Re: Bash Blues. TerraTrans Security (Feb 14)
- A different bash blues admin (Feb 15)
- RE: A different bash blues Adam Gilmore (Feb 16)
- A different bash blues admin (Feb 15)
- RE: Bash Blues. Adam Gilmore (Feb 14)
- Re: Bash Blues. Peter Pentchev (Feb 14)