Re: Solaris ipcs vulnerability

From: Robert G. Ferrell (rootat_private)
Date: Tue Apr 17 2001 - 05:26:16 PDT

  • Next message: neme-dhcat_private: "Advisory for Lotus Domino webserver"

    >PLATFORM>> solaris 2.7/SPARC
    >
    ><----snip---->
    >$ uname -a
    >SunOS <host> 5.7 Generic_106541-14 sun4u sparc
    >$
    >$ TZ=`/usr/local/bin/perl -e 'print "A"x2048'`
    >$
    >$ /bin/ipcs
    >Segmentation Fault
    >$
    >$ /usr/bin/sparcv7/ipcs
    >/usr/bin/sparcv7/ipcs: /dev/ksyms is not a 32-bit kernel namelist
    >$
    >$ /usr/bin/sparcv9/ipcs
    >Segmentation Fault
    
    Same behavior on my box:
    
    # uname -a
    SunOS <host> 5.7 Generic_106541-10 sun4u sparc SUNW,Ultra-5_10
    #
    # TZ=`perl -e 'print "A"x2048'`
    #
    # /bin/ipcs
    Segmentation Fault
    #
    # /usr/bin/sparcv7/ipcs
    /usr/bin/sparcv7/ipcs: /dev/ksyms is not a 32-bit kernel namelist
    #
    # /usr/bin/sparcv9/ipcs
    Segmentation Fault
    
    
    Anything above 1198 "A's" seg faults /bin/ipcs and /usr/bin/sparcv9/ipcs.
    
    Cheers,
    
    RGF
    
    Robert G. Ferrell, CISSP
    Information Systems Security Officer
    National Business Center
    U. S. Dept. of the Interior
    Robert_G_Ferrellat_private
    ========================================
     Who goeth without humor goeth unarmed.
    ========================================
    



    This archive was generated by hypermail 2b30 : Tue Apr 17 2001 - 11:42:02 PDT