Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Bugtraq: Re: Buffer Overflow in ActivePerl?

Re: Buffer Overflow in ActivePerl?

From: Axel Beckert <beckert_at_ecos.de>
Date: Tue, 18 May 2004 11:03:40 +0200

Hi!

Am Mon, May 17, 2004 at 10:23:56PM +0200, Oliver_at_greyhat.de schrieb:
> i played around with ActiveState's ActivePerl for Win32, and crashed
> Perl.exe with the following command:
>
> perl -e "$a="A" x 256; system($a)"
>
> I wonder if this bug isnt known?!? Because system() is a very common
> command....
> Can anybody reproduce this?

I can confirm this for Perl v5.8.0 built for MSWin32-x86-multi-thread
(Binary build 805 provided by ActiveState Corp.) on W2K.

My first thought was that the nested double-quotes maybe the reason,
but even

  perl -e "$a='A' x 256; system($a)"

crashes.

  perl -e "system('A'x256)"

chrashes also btw.

            Kind regards, Axel Beckert

-- 
-------------------------------------------------------------
Axel Beckert      ecos electronic communication services gmbh
it security solutions * web applications with apache and perl
Mail:       Tulpenstrasse 5       D-55276 Dienheim near Mainz
E-Mail:     beckert_at_ecos.de       Voice:     +49 6133 939-220
WWW:        http://www.ecos.de/   Fax:       +49 6133 939-333
-------------------------------------------------------------
Received on May 18 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]