[Full-Disclosure] Re: /bin/mail & glibc

From: Mark (mark_at_vulndev.org)
Date: 05/29/03

  • Next message: phrack staff: "[Full-Disclosure] PHRACK MAGAZINE Call for Papers (#61)"
    To: full-disclosure@lists.netsys.com
    Date: 29 May 2003 12:39:08 +0100
    

    Sorry I am immensely bored today so actually reading email!

    its actually a problem with /bin/mail and how it handles the CC field.

    /bin/mail -s Test -c `perl -e 'print "A" 8224'` root@localhost

    segfaults and overwrites eip at 8224 characters (segfaults without eip
    at 8220)

    dont have to be using zsh to create this problem.

    there isnt really alot of worry unless /bin/mail was setuid/setgid...

    easy to spawn a shell.. I've put a messy perl exploit together
    (www.vulndev.org) run it, insert your '.' and <CR> and you should get a
    shell.

    -- 
    		         Mark
    		   www.vulndev.org
    	'If ignorant both of the enemy and yourself,
    	you are certain in every battle to be in peril'
       If you know yourself, knowing the enemy does not matter.
    		-- Sun Tzu - The Art of War
    			(Adapted)
    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: phrack staff: "[Full-Disclosure] PHRACK MAGAZINE Call for Papers (#61)"

    Relevant Pages

    • Re: su segfault revisited
      ... > segfaults from the su program on RH7.2. ... The su command from the unpatched sh-utils-2.0.11 package ... In the original version su does not wait for a shell ... Kasper Dupont -- der bruger for meget tid på usenet. ...
      (comp.os.linux.security)
    • Re: "ulimit -s" has no effect?
      ... Mathias Waack writes: ... > Have you tried it with a different shell? ... But I'm using a bash where ulimit is a builtin. ... segfaults at about depth 7000+ ...
      (comp.lang.python)
    • Re: su segfault revisited
      ... > segfaults from the su program on RH7.2. ... The su command from the unpatched sh-utils-2.0.11 package ... bug. ... In the original version su does not wait for a shell ...
      (comp.os.linux.security)