Re: More telnet Daemon Fun

From: Elliot Lee (sopwithat_private)
Date: Tue Dec 02 1997 - 22:11:52 PST

  • Next message: Zack Weinberg: "Re: longpath.sh"

    On Mon, 1 Dec 1997, Aaron Campbell wrote:
    
    > Thanks to Jason Parsons <rootat_private> for pointing this one out:
    [telnet bug snipped]
    > Segmentation fault (core dumped)
    > [fx@somehost fx]$ ls -l core
    > -rw-------   1 fx       nnh        315392 Dec  1 21:51 core
    > [fx@somehost fx]$
    >
    > That's 256 characters up there, BTW. Also, note we're setting the DISPLAY
    > variable this time, not TERM.
    
    On Red Hat Linux 5.0, which uses glibc and a newer netkit, if I follow the
    above procedure and telnet to either localhost, a Solaris box, or a 4.2
    box, it just hangs when I telnet with the long $DISPLAY, and I tire of
    waiting and kill the telnet client.
    
    If I telnet from a RHL 4.2 box to anything, it does the segfault. This
    seems to indicate that there is a buffer overflow in old(er) versions of
    the telnet client.
    
    No joy,
    -- Elliot                       Seen on comp.os.linux.development.system:
    "I WOULD LIKE TO INSERT SOME SYSTEM CALL IN LINUX.  BUT I DON'T KNOW WHERE
    IS THE KERNEL SOURCE AND HOW TO COMPILE THE KERNEL PLEASE HELP ME!
    FROM censored -MY EMAIL DOESN'T WORK."
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:34:03 PDT