[10401] in bugtraq

home help back first fref pref prev next nref lref last post

Buffer overflow in ftpd and locate bug

daemon@ATHENA.MIT.EDU (Sergey V. Kolychev)
Fri Apr 30 14:37:27 1999

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id: <Pine.LNX.3.96.990430105441.23881A-100000@gw.al.lg.ua>
Date: 	Fri, 30 Apr 1999 11:07:20 +0300
Reply-To: "Sergey V. Kolychev" <ksv@GW.AL.LG.UA>
From: "Sergey V. Kolychev" <ksv@GW.AL.LG.UA>
To: BUGTRAQ@NETSPACE.ORG

Hi.

  I had problem with locate from findutils-4.1.24.rpm from Redhat-5.1
It segfaults if we have huge directory at incoming ftp which created
by exploits for ftpd realpath hole. My ftpd is patched. Those exploits
,i think, should not afraid me, but if updatedb puts to locate database
that directory then locate segfaults. ( getline.c 104 row by gdb )
I guess it can be used for running arbitrary commands if root runs locate.

I had look to latest Redhat-6.0 findutils-4.1.31.rpm but it still
based on findutils-4.1 as well as findutils-4.1.24 and haven't any
patches from redhat concerning subject and I am sure it stiil vulnerable.


   ----------------------Alchevsk Linux User Group-----------------------
      I don't call, I don't cry , I don't sorry.
      All will gone like a white appletreeses's smoke... (S.Esenin)
      http://www.ic.al.lg.ua/~ksv | e-mail: ksv@gw.al.lg.ua
      PGP key & Geekcode: finger ksv@gw.al.lg.ua

home help back first fref pref prev next nref lref last post