|
|||||||||||
|
Re: slocate vulnerability
From: Barry K. Nathan <barryn(at)pobox.com>
Date: Thu Jan 30 2003 - 06:50:46 EST On Wed, Jan 29, 2003 at 10:49:22PM +1000, Adam Gilmore wrote: > Below is an advisory on a buffer overflow in slocate 2.6.1. I can't > replicate the same error in gdb as the advisory and I don't believe it's > a buffer overflow at all. [snip] Here's what I'm getting on a Mandrake 9.0 box (running under a Connectix Virtual PC for Windows 5.1 trial, FWIW):
(gdb) run -c `perl -e "print 'A' x 1024"` -r `perl -e "print 'A' x
1024"`
If I just run it from the command prompt without going through gdb: $ /usr/bin/slocate -c `perl -e "print 'A' x 1024"` -r `perl -e "print 'A' x 1024"` warning: slocate: warning: database /var/lib/slocate/slocate.db' is more than 8 days old Segmentation fault -Barry K. Nathan <barryn@pobox.com> Received on Thu Jan 30 11:37:36 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:37 EDT |
||||||||||
|
|||||||||||