This is the mail archive of the
libc-alpha@sources.redhat.com
mailing list for the glibc project.
Re: Traceroute exploit + story (fwd)
- To: Daniel Jacobowitz <dmj+ at andrew dot cmu dot edu>
- Subject: Re: Traceroute exploit + story (fwd)
- From: Ulrich Drepper <drepper at redhat dot com>
- Date: 05 Oct 2000 13:47:12 -0700
- Cc: Chris Evans <chris at scary dot beasts dot org>, security-audit at ferret dot lmh dot ox dot ac dot uk, libc-alpha at sourceware dot cygnus dot com
- References: <Pine.LNX.4.21.0010051953300.10542-100000@ferret.lmh.ox.ac.uk><20001005163626.A9438@drow.them.org>
- Reply-To: drepper at cygnus dot com (Ulrich Drepper)
Daniel Jacobowitz <dmj+@andrew.cmu.edu> writes:
> I don't think this is exploitable, esp. since we do not seem to malloc
> until afterwards... but perhaps this should be fixed.
Once you show me how to exploit it I'll change it. With other words:
there is no way this makes a difference.
--
---------------. ,-. 1325 Chesapeake Terrace
Ulrich Drepper \ ,-------------------' \ Sunnyvale, CA 94089 USA
Red Hat `--' drepper at redhat.com `------------------------