Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: [ Hackerslab bug_paper ] Linux dump buffer overflow

Re: [ Hackerslab bug_paper ] Linux dump buffer overflow

From: Przemyslaw Frasunek <venglin_at_FREEBSD.LUBLIN.PL>
Date: Thu, 2 Mar 2000 06:50:07 +0100

On 01-Mar-2000 Derek Callaway wrote:
> (gdb) #0 getenv (name=0x40111a70 "") at ../sysdeps/generic/getenv.c:88
>>From this gdb session, it appears that there _could_ be a problem with
> the way that glibc's time functions behave.

No. getenv() fails because *envp, argc, **argv are AFTER pathname[]
buffer and gets overwritten.

Of course, it is still exploitable.

--
* Fido: 2:480/124 ** WWW: http://www.freebsd.lublin.pl ** NIC-HDL: PMF9-RIPE *
* Inet: venglin_at_freebsd.lublin.pl ** PGP: D48684904685DF43  EA93AFA13BE170BF *
Received on Mar 01 2000
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos