OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: [rootshell.com] Xterm DoS Attack
From: gavinaCSIS.GVSU.EDU
Date: Fri Jun 02 2000 - 15:46:57 CDT


On Thu, 1 June 2000, Kit Knox wrote:
>
> /*
> *
> * xterm Denial of Service Attack
> * (C) 2000 Kit Knox <kitrootshell.com> - 5/31/2000
> *
> * Tested against: xterm (XFree86 3.3.3.1b(88b) -- crashes
> * rxvt v2.6.1 -- consumes all available memory and then
> * crashes.

aterm 0.3.6 is not vulnerable. When you cat a file containing that
string, it displays nothing. Using a text editor, you can see the
contents.

------------------------
"He who rides the pony must someday fall."
     - Andrew Wood