OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Blake R. Swopes (bhodiBIGFOOT.COM)
Date: Mon Feb 12 2001 - 17:46:20 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Considering what overflows the buffer (your username), it would seem that
    you'd need root access to begin with in order to craft an exploit. Am I
    wrong?

    Of course, maybe this could be some exotic new addition to a rootkit.

    > -----Original Message-----
    > From: Bugtraq List [mailto:BUGTRAQSECURITYFOCUS.COM]On Behalf Of
    > Flatline
    > Sent: Saturday, February 10, 2001 3:38 PM
    > To: BUGTRAQSECURITYFOCUS.COM
    > Subject: vixie cron possible local root compromise
    >
    >
    > - Introduction:
    >
    > Paul Vixie's crontab version 3.0.1-56 contains another buffer overflow
    > vulnerability.
    > I'm not sure whether it's exploitable or not, it needs to be
    > fixed however.
    >
    >