csh/tcsh vulnerability

From: Á¤ ÈÆ¿µ (dragory1@hotmail.com)
Date: 06/27/02


From: "Á¤ ÈÆ¿µ" <dragory1@hotmail.com>
To: vuln-dev@securityfocus.com
Date: Thu, 27 Jun 2002 03:41:57 +0000

OS : Solaris 8
 
[sf280r]#/home/dragory> bash
[dragory@sf280r dragory]$ export HOME=`perl -e 'print "x"x5000'`
[dragory@sf280r dragory]$ su
Password:(input correct password)
Segmentation Fault (core dumped)
[dragory@sf280r dragory]$ ls -l core
-rw------- 1 root 580464 Jun 27 12:29 core
[sf280r]#/home/dragory> gdb -q tcsh core
(no debugging symbols found)...Core was generated by `tcsh'.
Program terminated with signal 11, Segmentation Fault.
#0 0x29be4 in doglob ()
 
Is this vulnerable?

_________________________________________________________________
MSN Explorer°¡ ÀÖÀ¸¸é Hotmail »ç¿ëÀÌ ÈξÀ Æí¸®ÇØ Áý´Ï´Ù. Áö±Ý
http://explorer.msn.co.kr/ ¿¡¼­ ¹«·á·Î ´Ù¿î·ÎµåÇϼ¼¿ä.



Relevant Pages

  • Re: stack overflow help ..
    ... (no debugging symbols found)...(no debugging symbols ... Program received signal SIGSEGV, Segmentation fault. ...
    (Security-Basics)
  • stack overflow help ..
    ... (no debugging symbols found)...(no debugging symbols ... Program received signal SIGSEGV, Segmentation fault. ...
    (Security-Basics)
  • RE: stack overflow help ..
    ... Do an "info frame" in gdb. ... (no debugging symbols found)...(no debugging symbols ... Program received signal SIGSEGV, Segmentation fault. ...
    (Security-Basics)
  • Re: [Full-Disclosure] some small bugs.
    ... > mtv@mercuzio~$ dpsinfo ... GNU gdb 6.1-debian ... This GDB was configured as "i386-linux"...(no debugging symbols found)...Using ...
    (Full-Disclosure)
  • gliv segfaults
    ... Since several days I'm trying to run gliv, and all I get is a "Segmentation fault". ... GNU gdb 5.3-debian ... This GDB was configured as "powerpc-linux"...(no debugging symbols found)... ...
    (Debian-User)