Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: GnuPG 1.2.3, 1.3.3 external HKP interface format string issue

Re: GnuPG 1.2.3, 1.3.3 external HKP interface format string issue

From: David Shaw <dshaw_at_jabberwocky.com>
Date: Wed, 3 Dec 2003 13:48:16 -0500

On Wed, Dec 03, 2003 at 04:30:38PM +0300, S-Quadra Security Research wrote:
> if(gotit)
> {
> // S-Quadra: here is where format string bug lives
> fprintf(output,line);
> if(strcmp(line,"-----END PGP PUBLIC KEY BLOCK-----\n")==0)
> break;
> }

This one is indeed a problem.

> if(strcmp(line,"-----BEGIN PGP PUBLIC KEY BLOCK-----\n")==0)
> {
> // S-Quadra: here is where format string bug lives
> fprintf(output,line);
> gotit=1;
> }

But this one is not. You can't get to the dangerous fprintf without
"line" being verified as safe.

David
Received on Dec 03 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]