Re: csh/tcsh vulnerability

From: Idan l. (shadow@x-war.net)
Date: 06/27/02


From: Idan l. <shadow@x-war.net>
To: "Á¤ÈÆ¿µ" <dragory1@hotmail.com>
Date: Thu, 27 Jun 2002 12:26:15 +0000

On Thursday 27 June 2002 03:41, you wrote:
> OS : Solaris 8
>
> [sf280r]#/home/dragory> bash
> [dragory@sf280r dragory]$ export HOME=`perl -e 'print "x"x5000'`
> [dragory@sf280r dragory]$ su
> Password:(input correct password)
> Segmentation Fault (core dumped)
> [dragory@sf280r dragory]$ ls -l core
> -rw------- 1 root 580464 Jun 27 12:29 core
> [sf280r]#/home/dragory> gdb -q tcsh core
> (no debugging symbols found)...Core was generated by `tcsh'.
> Program terminated with signal 11, Segmentation Fault.
> #0 0x29be4 in doglob ()
>
> Is this vulnerable?
>
>
>
> _________________________________________________________________
> MSN Explorer°¡ ÀÖÀ¸¸é Hotmail »ç¿ëÀÌ ÈξÀ Æí¸®ÇØ Áý´Ï´Ù. Áö±Ý
> http://explorer.msn.co.kr/ ¿¡¼­ ¹«·á·Î ´Ù¿î·ÎµåÇϼ¼¿ä.

Well depend if you su to another user for example user narf
And you can overflow it , It is a vulnerability.



Relevant Pages

  • Vulnerability in SETI@home
    ... SETI@home is a distributed project that ... this vulnerability is NOT exploitable in the default installation. ... Segmentation fault ... GDB is free software, covered by the GNU General Public License, and you are ...
    (Vuln-Dev)
  • Re: Vulnerability in SETI@home
    ... Segmentation fault ... > SETI@home is a distributed project ... this vulnerability is NOT exploitable in the default ... > GNU gdb 5.0rh-5 Red Hat Linux 7.1 ...
    (Vuln-Dev)
  • Re: [Full-Disclosure] ipcs on HP-UX 11.0
    ... I found a vulnerability with ipcs a while back, ... Segmentation fault ... to get any information from Compaq on this issue. ... > All ipcs vulnerabilities I know about are on HP Tru64. ...
    (Full-Disclosure)
  • Fresh installation: Segmentation fault
    ... I followed the instructions on http://www.pdc.kth.se/heimdal/heimdal.html to install heimdal kerberos, but when I run kinit me and enter the correct password it spits out Segmentation fault. ... Do you know why the Segmentation fault error could be occuring. ...
    (Debian-User)