[3842] in bugtraq
Re: Linux login buffer overflow
daemon@ATHENA.MIT.EDU (Dave G.)
Sun Dec 22 20:32:27 1996
Date: Sun, 22 Dec 1996 16:46:18 -0500
Reply-To: "Dave G." <daveg@escape.com>
From: "Dave G." <daveg@escape.com>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
After a quick look through, this doesnt look too dangerous. I doubt someone
could get it to exec a shell.
Same reason why rlogin was unexploitable, main never returns, only exits.
However, it is still a potential problem, just not another return address
overwrite.
Dave G.
<daveg@escape.com>
http://www.escape.com/~daveg