Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Can anyone verify a core dump on /sbin/mingetty - FOLLOW UP - Getty also dumping - AGETTY too

Re: Can anyone verify a core dump on /sbin/mingetty - FOLLOW UP - Getty also dumping - AGETTY too

From: KF <dotslash_at_snosoft.com>
Date: Mon, 03 Dec 2001 17:25:07 -0500

Actually agetty IS vulnerable... it just needed a little more lovin.

[root_at_linux elguapo]# agetty `perl -e 'print "A" x 9000'` `perl -e
'print "A" x
 9000'`
Segmentation fault (core dumped)

-KF

Bill Weiss wrote:
>
> Scott Mackenzie(smackenz_at_brad.ac.uk)@Mon, Dec 03, 2001 at 08:07:50PM +0000:
> > SEE MESSAGE :
> > 'Can anyone verify a core dump on /sbin/mingetty'
> > for the original post
> >
> > The reason why there is no core dump from /sbin is because I didn't have
> > write access - should have noticed that but there you go.
> >
> > Ok, bit more information:
> >
> > This problem is positive in the following systems:
> > * note there could and probably are more but I've only had word of the
> > following systems being tested
> >
> > Red-Hat 6.0 onwards (not tested any before) upto and including 7.2
> > Mandrake 8.0 2.4.3-20mdksmp (presumably similar to redhat here)
> > turbolinux 6.0
> > SCO unix 5.0.5
> >
> > (this information was quickly gathered by several people; thanks everyone)
>
> Slackware 7.0 (maybe 8.0) uses agetty, which is not vunerable, as far as I can tell.
> It just spits out a usage error.
>
> -- Bill Weiss
Received on Dec 03 2001

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos