Re: [exim-dev] exim_dbmbuild buffer overflow

Página superior
Eliminar este mensaje
Responder a este mensaje
Autor: Tom Kistner
Fecha:  
A: alberto barbaro
Cc: exim-dev
Asunto: Re: [exim-dev] exim_dbmbuild buffer overflow
alberto barbaro wrote:

> sh-2.05b$ echo "a" > a.txt && exim_dbmbuild a.txt `perl -e 'print"A"x5000'`
> Segmentation fault


That proves you can break anything with a large enough hammer.

> Ustrcpy(temp_dbmname, argv[arg+1]);    <--- needs more control


Why?

> Please write me back soon


Why?

(Hint: exim_dbmbuild is not installed setuid, nor is it invoked by a
remote operation).

/tom