Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: format strings vulns in /bin/login and /usr/bin/passwd

From: Brian Hatch <vuln-dev(at)ifokr.org>
Date: Mon Jan 27 2003 - 14:31:58 EST

> Hello while doing a scan for format strings vulns on util-linux package
...

This doesn't mean that these are vulnerable function calls. For example

        fprintf(stderr, "Sorry, your password is invalid"); or

        syslog(LOG_NOTICE, "User %s is a moron", username);

are completly legitimate ways to call these functions and don't have any vulnerability in them that anyone knows about currently. The presense of a function that *could* be used poorly doesn't mean it *is* used poorly. Sounds like you're just grepping for potential abuses. Now you need to go and look at how the functions are actually called. For example

        syslog(LOG_NOTICE, some_char_array_using_user_input);

Do you need help?X

is definately a bad way to write it. Whether the call is actually exploitable is a different question. But regardless it should be fixed.

--
Brian Hatch                  Linux. The OS for
   Systems and                those with an IQ
   Security Engineer          greater than 98.
http://www.ifokr.org/bri/

Every message PGP signed

  • application/pgp-signature attachment: stored
Received on Mon Jan 27 14:47:13 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:37 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library