Re: OpenSSH Vulnerability

From: Adam (adam_at_zeusinternet.net)
Date: 09/19/03

  • Next message: Steven Hill: "Re: controlling ebp/eip of a frame, does it always lead to possible code execution?"
    To: <vuln-dev@securityfocus.com>
    Date: Fri, 19 Sep 2003 09:25:17 +1000
    
    

    I can't see any way you could use compression to crash the process. I did
    try this method, but the minute we try to buffer_append() the data to the
    output buffer (in buffer_uncompress()), the data we try to append >1mb
    therefore buffer_append_space() crashes BEFORE we're actually able to
    "allocate" the required space. i.e. it crashes on the wrong fatal() call
    for what we want. Therefore we have to somehow allocate <1mb at a time to
    successfully overflow. So I don't see quite how we could crash the process
    by sending it a compressed 10mb packet or anything.

    Any suggestions?

    ***************************************************************
    This email and any files transmitted with it are confidential and
    intended solely for the use of the individual or entity to whom they
    are addressed. If you are not the intended recipient any use,
    distribution, disclosure or copying of this information is prohibited.
    If you have received this email in error please notify the sender
    immediately and delete it and any attachments from your system
    ***************************************************************


  • Next message: Steven Hill: "Re: controlling ebp/eip of a frame, does it always lead to possible code execution?"

    Relevant Pages

    • Re: What to do when Word constantly crashes?
      ... crash", but I use them all day every day (I am a professional Technical ... Microsoft was one of the first to realise that being "The first to be wrong" ...  Keep the updates up to date. ...  Your crashes should stop! ...
      (microsoft.public.mac.office.word)
    • Several, bring coffie
      ... >>> The point is that not that RosAsm crashes. ... Obviously the best way to prevent this> happening is to make an application which never crashes, but,> even then, there are events which can cause a crash -- such as ... this is not a LuxAsm problem...this ...
      (alt.lang.asm)
    • Re: Word 2004 crashes when cutting text - FIXED!!!
      ... I could not do it because I got also a crash when copying such ... I later on found that I could copy/paste in other Mac with Word ... files which generated the crashes did not have pictures for sure. ... >> And now it seems that frequent savings manually can also ...
      (microsoft.public.mac.office.word)
    • Re: Word 2004 crashes when cutting text - FIXED!!!
      ... > for you to send me directly the text file of your Crash Log? ... >> external FireWire disk (different for each Mac). ... it is easier "Shift Command Home" on a 29-page long document. ... 99% of my crashes are on documents without tables. ...
      (microsoft.public.mac.office.word)
    • Re: For Frank Krygowskis helmet files
      ... Take a look at all the crashes in Velo ... backwards off her bike. ... The bikes tangled and I went over the bars. ... My second over-the-bars was a slow speed crash in a cyclo-cross race ...
      (rec.bicycles.tech)