Re: [RHSA-1999:028-01] Buffer overflow in libtermcap tgetent()

From: Michal Zalewski (lcamtufat_private)
Date: Sat Jul 03 1999 - 21:38:57 PDT

  • Next message: Michal Zalewski: "[Linux] glibc 2.1.x / wu-ftpd <=2.5 / BeroFTPD / lynx / vlock /"

    On Thu, 19 Aug 1999, Tymm Twillman wrote:
    
    > And as Chris Evans pointed out on linux-security, libncurses on RedHat
    > is built with -DPURE_TERMINFO, which keeps it from using the buggy
    > buffer code in libtermcap.
    
    ...not quite true - we're able to cause at least several SEGVs in ncurses'
    tgetent() function by putting junk into terminfo files. Simply, try some
    brute-force algorithms. I don't want to discuss about possible
    consequences of this bug, as we haven't checked carefully terminfo format,
    nor parser code.
    
    _______________________________________________________________________
    Michal Zalewski [lcamtufat_private] [link / marchew] [dione.ids.pl SYSADM]
    [Marchew Industries] ! [http://lcamtuf.na.export.pl] bash$ :(){ :|:&};:
    [voice phone: +48 (0) 22 813 25 86] ? [cellular phone: (0) 501 4000 69]
    Iterowac jest rzecza ludzka, wykonywac rekursywnie - boska [P. Deutsch]
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:57:21 PDT