openssh buffer_append_space vulnerability

From: Joseph Blade (
Date: 06/11/04

  • Next message: Bipin Gautam: "Antivirus/Trojan/Spyware scanners DoS [summary]"
    Date: Fri, 11 Jun 2004 09:30:00 -0400

    Good Morning To All,

    Long time listener, first time caller.

    Has anyone in the community seen any progress in the
    buffer_append_space() vulnerability, which sets the buffer's
    allocated int when it isn't allocated?

    The last process that I used last September was to use data compression
    to crash buffer_append(). When this was done, the data would cause a
    crash before the space was allocated. At that point I had "deer in the

    If anyone has any ideas or knows of a poc in regards to this
    vulnerability, I would greatly appreciate it.



  • Next message: Bipin Gautam: "Antivirus/Trojan/Spyware scanners DoS [summary]"

    Relevant Pages