[20689] in bugtraq

home help back first fref pref prev next nref lref last post

Re: RH7.0: man local gid 15 (man) exploit

daemon@ATHENA.MIT.EDU (PJ)
Thu May 17 04:30:05 2001

Date: Wed, 16 May 2001 16:55:07 -0700
From: PJ <briareos@otherlands.net>
To: Stephen Shirley <diamond@skynet.ie>
Cc: Bugtraq Mailing List <bugtraq@securityfocus.com>
Message-ID: <20010516165507.A32075@elvander.otherlands.net>
Reply-To: PJ <briareos@otherlands.net>
Mail-Followup-To: PJ <briareos@otherlands.net>,
	Stephen Shirley <diamond@skynet.ie>,
	Bugtraq Mailing List <bugtraq@securityfocus.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.LNX.4.32.0105161802130.26654-100000@skynet>; from diamond@skynet.ie on Wed, May 16, 2001 at 06:06:12PM +0100

FYI, still doesn't work on Slackware 7.1

$ man -S : blah
No manual entry for blah
$

$ man -S ::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: blah
blah: nothing appropriate
$

I have tried the other command to try to get man to segfault with a
supplied arguement, still nothing.  

$ man -S `perl -e 'print ":" x 100'` blah
No manual entry for blah
$

On Wed, 16 May 2001, Stephen Shirley wrote:

> Hi,
> 	The info posted to get man to seg fault is slightly incorrect. You
> need to supply some text as the name of a man page - otherwise man will
> reject all input. The number of :'s is irrelevat too - one is enough.
> 
> man -S : blah
> will cause a seg fault. This has been confirmed on debian 2.2 woody, and I
> submitted a patch to fix it. The new version is in unstable - ver
> 2.3.18-2. From the changelog of 2.3.18-2:
> 
>   * man would segfault if the argument to -S contained only colons, and
>     incidentally treated an empty argument to -S wrongly. Both cases now
>     use the standard list of sections instead (thanks, Colin Phipps and
>     Stephen Shirley; closes: #97553, #97566).
> 
> Steve
> -- 
> "My mom had Windows at work and it hurt her eyes real bad"
> 
> 
> 

PJ

-- 
My brain needs a new OS - it can't stay up for much longer than 24 hours without a reboot.

home help back first fref pref prev next nref lref last post