Re: man bugs might lead to root compromise (RH 6.1 and other

From: H D Moore (hdmat_private)
Date: Mon Feb 28 2000 - 03:54:26 PST

  • Next message: Veille Technologique: "DOS in TrendMicro OfficeScan"

    I tried PAGERas well as every other environment variable I could tell it
    read, no luck.  The PAGER just gives me "AAAAAAAAA" ... "AA: Command not
    found."
    
    -HD
    
    Michal Zalewski wrote:
    >
    > On Sun, 27 Feb 2000, H D Moore wrote:
    >
    > > Hi,
    > >
    > > I could not reproduce this on a SuSE 6.2 system running:
    > >
    > > man, version 2.3.10, db 2.3.1, July 12th, 1995
    > > (G.Wilfordat_private)
    > >
    > > My copy is setgid man and I also subjected it to 4,8, and 20 kb buffers
    > > in every envrionment variable it uses without it flinching.
    >
    > Try setting PAGER instead of MANPAGER - older man version used it.
    >
    > _______________________________________________________
    > Michal Zalewski * [lcamtufat_private] <=> [AGS WAN SYSADM]
    > [dione.ids.pl SYSADM] <-> [http://lcamtuf.na.export.pl]
    > [+48 22 551 45 93] [+48 603 110 160] bash$ :(){ :|:&};:
    > =-----=> God is real, unless declared integer. <=-----=
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:37:52 PDT