Vulnerability Development mailing list archives

su core dumped with signal 3. BSD/OS 3.0, 3.1


From: Ivan Aleksandrov <mail () rayd info>
Date: 11 Mar 2003 17:30:03 -0000



rayd@mtelecom:~$ id
uid=127(rayd) gid=0(wheel) groups=0(wheel)
rayd@mtelecom:~$ su             <------------- (I send "control symbol")
Password:Quit (core dumped)     
rayd@mtelecom:~$

rayd@mtelecom:~$ uname -srm
BSD/OS 3.1 i386
rayd@mtelecom:~$ ls -la `whereis su`
-r-sr-xr-x  1 root  bin  2868 Jan 21  1997 /usr/bin/su*
rayd@mtelecom:~$ ls -la su.core
-rw-------  1 root  wheel  184320 Mar 11 22:17 su.core

root@mtelecom:/usr/home/rayd# gdb --core=su.core
GDB 4.16 (i386-unknown-bsdi3.0), Copyright 1996 Free Software Foundation, 
Inc.
Core was generated by `su'.
Program terminated with signal 3, Quit.
#0  0xa004cbde in ?? ()

It is a serious bug?
Possible to write exploit? or with signal 3 it's impossible?

WTF?

--
RAYD <mail () rayd info>
RAYD-RIPN, rayd@efnet


Current thread: