From: tomw@orac.engr.sgi.com (Tom Weinstein)
 To: perry@piermont.com
 Message Hash: 49cc9263d8eab4168d6da08a52f40e73a565bc31899bd2fbe63144016e14acf8
 Message ID: <199509230049.RAA06102@orac.engr.sgi.com>
 Reply To: N/A
 UTC Datetime: 1995-09-23 00:50:37 UTC
 Raw Date: Fri, 22 Sep 95 17:50:37 PDT
From: tomw@orac.engr.sgi.com (Tom Weinstein)
Date: Fri, 22 Sep 95 17:50:37 PDT
To: perry@piermont.com
Subject: Re: netscape bug
Message-ID: <199509230049.RAA06102@orac.engr.sgi.com>
MIME-Version: 1.0
Content-Type: text/plain
I said:
In article <DFALB4.A5u@sgi.sgi.com>, "Perry E. Metzger" <perry@piermont.com> writes:
>> I can tell you in general terms -- I don't write MIPS assembler
>> myself. However, I will point out to you that you use an ancient
>> Sendmail, and that it uses syslog(3) on user produced data, and that
>> syslog uses a static buffer. Trick sendmail into logging something
>> very big, and you can do what you like. The 8lgm people wrote a demo
>> for Sparc as a proof of concept.
> Hmm, after having looked at the syslogd code, it looks like this
> particular bug has been fixed for at least several years.  However,
> there sure are a hell of a lot of fixed size buffers being alocated off
> the stack and some of them are being used in unsafe ways.
Whoops.  Having done a little more checking, it appears that this bug
does indeed occur in all current version of Irix.  There's a patch for
it (patch 825) that will be out imminently.
-- 
Sure we spend a lot of money, but that doesn't mean    |  Tom Weinstein
we *do* anything.  --  Washington DC motto             |  tomw@engr.sgi.com
Return to September 1995
Return to “tomw@orac.engr.sgi.com (Tom Weinstein)”
1995-09-23 (Fri, 22 Sep 95 17:50:37 PDT) - Re: netscape bug - tomw@orac.engr.sgi.com (Tom Weinstein)