Re: [Full-disclosure] Cygwin Bash Buffer Overflow (Cosmin Stejerean)

From: Stejerean, Cosmin (cstejere_at_cs.depaul.edu)
Date: 05/29/05

  • Next message: Nick FitzGerald: "[Full-disclosure] Spam exploiting MS05-016"
    Date: Sun, 29 May 2005 06:23:27 -0500
    To: <full-disclosure@lists.grok.org.uk>
    
    

    > Cygwin Bash Buffer Overflow
    > Author: Rodrigo Gutierrez <rodrigo@intellicomp.cl>
    > Affected: Versions of bash distributed by the cygwin project
    > vendor url: http://www.cygwin.com
    > Type: Local

    > Background.
    > Cygwin is a Linux-like environment for Windows. GNU BASH is the GNU
    > project's UNIX shell. It replaces the standard UNIX Bourne and Korn
    > shells.

    > Description

    > I think that cygwin people are cool, but Full Disclosure is a life
    style,
    > this is all you get guys, 8 megs.

    > PoC

    > you@cygwin:~ /usr/bin/bash `perl -e "print 'a'x8388600"`

    Which version of bash for Cygwin? I tried your PoC on the latest version
    of Cygwin and everything was fine.

    Cosmin Stejerean

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Nick FitzGerald: "[Full-disclosure] Spam exploiting MS05-016"

    Relevant Pages

    • Re: Building the kernel with Cygwin
      ... I've just built a linux kernel on my cygwin system using a ppc cross ... bash$ export PATH=/bin:$PATH ...
      (Linux-Kernel)
    • Re: Mount cygwin root on Windows root
      ... but I've recently been switching to using cygwin and bash. ... coincide with the Windows root "C:". ... Currently I have the cygwin installation on the root, ...
      (comp.unix.shell)
    • RE: Cygwin, ssh, and top
      ... David Rothenberger wrote on cygwin: ... For some reason, Debian miscalculated the COLUMNS ... > I recommend running ssh from bash in an rxvt window instead of using ...
      (Debian-User)
    • [Full-disclosure] Cygwin Bash Buffer Overflow
      ... Cygwin Bash Buffer Overflow ... GNU BASH is the GNU ... project's UNIX shell. ...
      (Full-Disclosure)
    • Re: cygwin issues using less in bash
      ... responds appropriately, even when I exit bash, I can still not see what ... I type until I open a new cygwin window. ... You're running bash under the default DOS-style window, ... And rxvt comes wit cygwin. ...
      (comp.unix.shell)