Re: HP-UX finger possible security hole

From: hofmannat_private-WUERZBURG.DE
Date: Wed May 27 1998 - 02:44:25 PDT

  • Next message: Zach White: "Re: about sendmail 8.8.8 HELO hole"

    Verified this on HP/UX 10.20 (B.10.20 A 9000/778).
    
    The string length limit actually is 80 chars. 81 will cause segfault.
    Interestingly, finger only prints 48 chars of the given username. But
    it does not crash until the string is longer than 80 chars.
    
    Bye,
    Frank Hofmann
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:54:53 PDT