Re: ecartis / listar PoC

From: KF (dotslash@snosoft.com)
Date: 04/26/02


Date: Fri, 26 Apr 2002 09:04:40 -0400
From: KF <dotslash@snosoft.com>
To: John Madden <weez@freelists.org>

The thing is this is the least of their worries... and as you said the
author IS working dilligently to fix the issues at hand. As for the
patch ... knock your self out heres the errant code.

[root@ghetto ecartis-1.0.0]# grep -n pathname"\[" src/core.c
80:char pathname[BIG_BUF];
[root@ghetto ecartis-1.0.0]# grep -n "sprintf(pathname" src/core.c
891: sprintf(pathname, "%s", argv[0]);

-KF

John Madden wrote:

>On Wednesday 24 April 2002 08:56 pm, KF wrote:
>
>>Heres some code for this post a while back ...
>>http://online.securityfocus.com/archive/82/258763
>>This is NOT the same issue in the my_strings.c there are MULTIPLE issues
>>in ecartis still and the same goes for listar...
>>This issue is a strcpy from argv to a fixed buffer .... nothing special.
>>
>
>Please see Ecartis' mailing list archives regarding these issues. They're
>aware of the problems and are working to resolve them.
>
>How about, instead of just telling us about there being multiple issues
>and posting an exploit, you post a patch to help fix the issues?
>
>Thanks,
> John
>
>
>
>
>
>
>
>



Relevant Pages

  • Re: ecartis / listar PoC
    ... author IS working dilligently to fix the issues at hand. ... knock your self out heres the errant code. ... >>This is NOT the same issue in the my_strings.c there are MULTIPLE issues ... >Please see Ecartis' mailing list archives regarding these issues. ...
    (Bugtraq)
  • Re: No Fix To My Merge Problem???
    ... multi-page merge with multiple conditions... ... Peter Jamieson was absolutely AWESOME with support for this issue. ... (search for 'Suzanne' and select the one with 14 or so posts). ... The number one fix that I wish I had come up with earlier was adding another ...
    (microsoft.public.word.vba.general)
  • Re: confusing problem
    ... that this is a really really inefficient way to determine tnow. ... SYSTEM function, and also on the existence of a DATE command, but it ... whatever the current directory happens to be is broken in multiple ways. ... You are having to fix the broken code anyway; ...
    (comp.lang.fortran)
  • Re: [Full-disclosure] How many vendors knowingly ship GA product with security vulnerabilities?
    ... had a fix ready, either for next release or vulnerability discovery, ... the API change goes to multiple code ... Then you have to send the CD off to be duplicated (even a *big* duplicating ...
    (Full-Disclosure)
  • Re: 3rd time is the charm! Linking CountIF formula
    ... Maybe you could use a different function (multiple times!): ... (You'll have to fix all the references--I got lazy!) ... BenJAMMIN wrote: ...
    (microsoft.public.excel.misc)