[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-Disclosure] Re: [ GLSA 200402-02 ] XFree86 Font Information File Buffer Overflow



> > Fatal server error:
> > Caught signal 11.  Server aborting
> >
> > no segfault or something...
> 
> hahahaha...give me a shell i'll check it out!!

people can't make mistakes without anybody making
fun off them :P

i copy paste the wrong lines. if logged in on the console
i get a segfault. using ssh i get:

[evert@server evert]$ X :0 -fp $PWD
Authentication failed - cannot start X server.
Perhaps you do not have console ownership?
[evert@server evert]$

so my real question was... is it still remotely (using a php
include with apache or something) to exploit the bug?

kind regards,
Evert



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html