[14173] in bugtraq

home help back first fref pref prev next nref lref last post

Re: [ Hackerslab bug_paper ] Linux dump buffer overflow

daemon@ATHENA.MIT.EDU (Lamagra Argamal)
Tue Mar 7 02:21:42 2000

Message-Id:  <20000303195341.10243.qmail@fiver.freemessage.com>
Date:         Fri, 3 Mar 2000 19:53:41 -0000
Reply-To: Lamagra Argamal <lamagra@HACKERMAIL.NET>
From: Lamagra Argamal <lamagra@HACKERMAIL.NET>
X-To:         bugtraq@securityfocus.com
To: BUGTRAQ@SECURITYFOCUS.COM

i checked RedHat's 5.2 dump (dump-0.3) and it doesn't seem vunerable in an exploitable way.
There's a minor heap-overflow though:

snipped from optr.c

msg(const char *fmt, ...)
{
	.......
        va_start(ap, fmt);
#else
        va_start(ap);
#endif
        (void) vfprintf(stderr, fmt, ap);
        (void) fflush(stdout);
        (void) fflush(stderr);
        (void) vsprintf(lastmsg, fmt, ap);
        va_end(ap);
	......
}

Lastmsg is a global variable size = 100

-lamagra
http://lamagra.seKure.de
http://www.b0f.com



Send someone a cool Dynamitemail flashcard greeting!! And get rewarded.
GO AHEAD! http://cards.dynamitemail.com/index.php3?rid=fc-41

home help back first fref pref prev next nref lref last post