Re: TCSH problems?

From: Alex (alexat_private)
Date: Wed Jun 06 2001 - 01:49:55 PDT

  • Next message: Michal Zalewski: "Re: nonsuid overflows... still at risk?"

    	After some ktracing, and code auditing by myself and a colleague,
    we believe the problem *may* infact be in libc's setenv() and getenv()
    functions.  We were able to duplicate the bug on various platforms, mostly
    causing signal 6s and dumping cores.  Feedback would be appreciated
    
    
    > > setenv HOME `perl -e 'print "/" x 10000'`
    
    					^ Length varies from 1024-10000
    for effectiveness on diffrent OSes.
    
    -Alex
    



    This archive was generated by hypermail 2b30 : Wed Jun 06 2001 - 08:26:23 PDT