[23170] in bugtraq

home help back first fref pref prev next nref lref last post

Re: /usr/bin/write (solaris2.x) Segmentation Fault

daemon@ATHENA.MIT.EDU (Rich Teer)
Thu Nov 15 23:23:27 2001

Date: Thu, 15 Nov 2001 19:56:20 -0800 (PST)
From: Rich Teer <richard.teer@rite-group.com>
To: SChoe <schoe@CheapTickets.COM>
Cc: <bugtraq@securityfocus.com>
In-Reply-To: <Pine.GSO.4.31.0111131605170.5128-100000@payt01.corp.cheaptickets.com>
Message-ID: <Pine.GSO.4.33.0111151952430.28944-100000@grover>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII

On Tue, 13 Nov 2001, SChoe wrote:

> solaris 2.7, 2.8
> ================
> $ uname -v
> Generic_106541-14

106541 isn't the Solaris 8 KJP...

Solaris 8 (at least from Generic_108528-09, I don't have
an FCS system to hand) isn't vulnerable:

	rich@mars5140# uname -a
	SunOS mars 5.8 Generic_108528-09 sun4u sparc SUNW,Ultra-1
	rich@mars5141# /usr/bin/write root `perl -e 'print "A" x 88'`
	Terminal name too long.


Ditto for the Solaris 9 Beta:

	rich@grover9141# uname -a
	SunOS grover 5.9 Beta sun4u sparc SUNW,Sun-Blade-100
	rich@grover9149# /usr/bin/write root `perl -e 'print "A" x 88'`
	Terminal name too long.

--
Rich Teer

President,
Rite Online Inc.

Voice: +1 (250) 979-1638
URL: http://www.rite-online.net


home help back first fref pref prev next nref lref last post