Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: [Linux] glibc 2.1.x / wu-ftpd <=2.5 / BeroFTPD / lynx / vlock / mc / glibc 2.0.x
From: daw () CS BERKELEY EDU (David Wagner)
Date: Wed, 1 Sep 1999 21:48:27 -0700


In article <14282.6738.523996.809083 () floh privat circular de>,
Norbert Warmuth  <nwarmuth () PRIVAT CIRCULAR DE> wrote:
An off-by-one error, hardly to exploit especially since the value written
is always '\0'.

Relying on that to protect you may not be prudent.  See
  http://www.geog.ubc.ca/snag/bugtraq/msg03213.html
for an example of an off-by-one error which only allowed to write a '\0'
yet was exploited in the field (!).


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]