Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: [linux-security] Re: identd hole?

Re: [linux-security] Re: identd hole?

From: lilo <TaRDiS_at_Mail.UTexas.EDU>
Date: Thu, 18 Jul 1996 06:51:49 -0500

On Tue, 16 Jul 1996, Dave G. wrote:

> As far as I know, there is no buffer overflow in atoi() under linux.
> This rumor was started when there was a problem in some IRC clients. At
> the time I took a look at atoi() and strtol(). Not only were there no
> buffer overflows, there were no buffers at all :).

Well, the problem has not been sufficiently debugged. The fact that it only
occurred in pre-5.3.9 ELF libc, and that it was universally resolved by
upgrading the libc to 5.3.12 (really we did spend a fair amount of time
verifying that behavior) seemed indicative of a library problem, and the
atoi() diagnosis was volunteered by someone with more time on their hands,
and possibly less skill.... :)

lilo
Received on Jul 18 1996

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos