[17705] in bugtraq
Re: Solaris libc locale bug exploit against non-exec stack
daemon@ATHENA.MIT.EDU (Christopher Allen Wing)
Mon Nov 20 14:05:35 2000
Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id: <Pine.SOL.4.02.10011200840540.18280-100000@ratt.engin.umich.edu>
Date: Mon, 20 Nov 2000 08:44:49 -0500
Reply-To: Christopher Allen Wing <wingc@ENGIN.UMICH.EDU>
From: Christopher Allen Wing <wingc@ENGIN.UMICH.EDU>
To: BUGTRAQ@SECURITYFOCUS.COM
Several people have pointed out that I'm a moron and that an empty string
is a valid name for an environment variable. :)
So, please disregard the previous message. It doesn't fix the
vulnerability in libc.
Thanks,
Chris Wing
wingc@engin.umich.edu