On Sat, 4 Mar 2000, Kris Kennaway wrote: > > extremely long URLs. I'm not going to give more examples here, as I'm > > afraid I might miss one or two that won't be fixed - developers, use your > > head, take a look at the code and fix every suspected piece of code, not > > only already published / described bugs. > > I have just disabled the lynx port/package in FreeBSD. We won't be > shipping it in FreeBSD 4.0, or until this gets addressed. It's a shame > because it's such a popular and useful tool, but the risk to users is just > too great. > > Thanks for notifying the world of these problems :) > I was trying to exploit lynx bug several times. It's true that lynx segfaults on long URLs, but exploiting it is (IMHO) impossible because lynx strips all nonprintable characters thus smugling RET address is impossible. I have never heard about ASCII only shellcode also :) I assume lynx bugs are unexploitable... P.S. You can compile lynx using StackGuard also (AFAIK only under Linux). -- Mariusz Wołoszyn Internet Security Specialist, Internet Partners, GTS Poland
This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:39:07 PDT