|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow
Subject: Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow
From: Theodor Ragnar Gislason (teddi
LINUX.IS)
Date: Fri Jan 07 2000 - 15:47:26 CST
- Next message: rudi carell: "Altavista followup"
- Previous message: Chris Adams: "Re: Handspring Visor Network HotSync Security Hole"
- In reply to: Brock Tellier: "Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow"
- Next in thread: Darren Reed: "Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow"
- Reply: Theodor Ragnar Gislason: "Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Thu, 6 Jan 2000, Brock Tellier wrote:
> >[Hackerslab bug_paper] Solaris chkperm buffer overflow
> >
> >[Hackerslab:/users/loveyou/buf]$ chkperm -n `perl -e 'print "x" x 200'`
> >Segmentation fault (core dumped)
> >
> >it is recommended that the suid bit is
> >removed from chkperm using command :
> >
> > chmod 400 /usr/vmsys/bin/chkperm
>
> Hrm, yeah, I found this one some months ago while I was checking out chkperm's
> ability to read bin-owned files. After some testing I concluded that, at
> least on SPARC, the function where the overflow occurs will exit() before it
> is allowed to return (and then return again), meaning that a buffer overflow
> exploit is probably not possible. I would be interested to see if anyone came
> to a different conclusion.
I also noticed this bug some time ago under similar circumstances and I
concluded that it is _NOT_ exploitable under i386.
-
DiGiT
- Next message: rudi carell: "Altavista followup"
- Previous message: Chris Adams: "Re: Handspring Visor Network HotSync Security Hole"
- In reply to: Brock Tellier: "Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow"
- Next in thread: Darren Reed: "Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow"
- Reply: Theodor Ragnar Gislason: "Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
This archive was generated by hypermail 2b27 : Mon Jan 10 2000 - 23:11:58 CST