Re: Buffer overflow in BASH

From: Peter J. Holzer (hjpat_private)
Date: Tue Apr 27 1999 - 07:38:15 PDT

  • Next message: Paul Gracy: "Re: Bug in WinNT 4.0 SP4"

    --RwGu8mu1E+uYXPWP
    Content-Type: text/plain; charset=us-ascii
    
    On 1999-04-19 14:59:06 -0400, Adam D. McKenna wrote:
    > I really don't see the point of people posting bash bugs here.
    > Especially not bugs in old versions. There are a lot of bash bugs, you
    > can't gain any extra priveleges by exploiting them though.
    
    You can, if you can trigger the bug in a script which is not running
    with your privileges - suid and cgi scripts are obvious examples.
    
    So, posting bash bug reports at least reminds people that using
    bash - especially old versions - for such scripts is not a good idea.
    
    	hp
    
    --
       _  | Peter J. Holzer             | Where do you want your keys
    |_|_) | Sysadmin WSR / Obmann LUGA  | to go today?
    | |   | hjpat_private               |     -- Tom Perrine <tepat_private>
    __/   | http://wsrx.wsr.ac.at/~hjp/ |        on bugtraq 1999-04-20
    
    --RwGu8mu1E+uYXPWP
    Content-Type: application/pgp-signature
    
    -----BEGIN PGP SIGNATURE-----
    Version: 2.6.3ia
    
    iQDQAwUBNyXL11LjemazOuKpAQGuOgXSAspM+uQI82xOlqzGWMZYID1a+lQQP0vz
    qRtr6UCaljhuZHwkmmf2Vh2gawvQUT97YA22boLtmPD4GutaXqxDatloOz5tIEg3
    xfdyAhip0BaTkk3BC4/BoKTFBrZzAF6Qqoj664IKmK7ct3BADe0U1m7i9Ab6rVzN
    Nz1TqM3PqihfYwbs1LtDbdp7Z+eLAhAZd2Pr4BuHWv9rz4JLS5rtfeNjENDngjWI
    1LFD1FftiiTF/+yCPQsQSnmRFw==
    =U3VK
    -----END PGP SIGNATURE-----
    
    --RwGu8mu1E+uYXPWP--
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:43:58 PDT