[14140] in bugtraq
Re: [ Hackerslab bug_paper ] Linux dump buffer overflow
daemon@ATHENA.MIT.EDU (Przemyslaw Frasunek)
Thu Mar  2 13:46:41 2000
Content-Type: text/plain; charset=iso-8859-2
Content-Transfer-Encoding: 8bit
Mime-Version: 1.0
Message-Id:  <XFMail.20000302065007.venglin@freebsd.lublin.pl>
Date:         Thu, 2 Mar 2000 06:50:07 +0100
Reply-To: Przemyslaw Frasunek <venglin@FREEBSD.LUBLIN.PL>
From: Przemyslaw Frasunek <venglin@FREEBSD.LUBLIN.PL>
X-To:         Derek Callaway <super@UDEL.EDU>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <Pine.LNX.4.10.10003010957570.3511-100000@pager.ce.net>
On 01-Mar-2000 Derek Callaway wrote:
> (gdb) #0  getenv (name=0x40111a70 "") at ../sysdeps/generic/getenv.c:88
>>From this gdb session, it appears that there _could_ be a problem with
> the way that glibc's time functions behave.
No. getenv() fails because *envp, argc, **argv are AFTER pathname[]
buffer and gets overwritten.
Of course, it is still exploitable.
--
* Fido: 2:480/124 ** WWW: http://www.freebsd.lublin.pl ** NIC-HDL: PMF9-RIPE *
* Inet: venglin@freebsd.lublin.pl ** PGP: D48684904685DF43  EA93AFA13BE170BF *