Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Vuln Dev
Bash Blues. Feb 13 2003 02:26PM
uk2sec oakey no-ip com (5 replies)
Re: Bash Blues. Feb 14 2003 08:24AM
Peter Pentchev (roam ringlet net)
On Thu, Feb 13, 2003 at 02:26:51PM +0000, uk2sec (at) oakey.no-ip (dot) com [email concealed] wrote:
> [ Moderator: Post Edited Accordingly ]
>
> uk2sec /bin/bash Advisory
>
> By sending a perl request on the GNU bash terminal we can cause a
> Segmentation Fault.
>
> Work done was based on:
> GNU bash, version 2.05a.0(1)-release (i686-pc-linux-gnu)
> (Redhat 7.3)
[snip]
> Background:
>
> During some work, I noticed GNU bash could be crashed by sending a
> malformed perl request to the terminal.
>
> example: `perl -e 'print "*/*" x 3500'`
> <bash crashes>

I cannot reproduce this in bash-2.05b.0(1)-release on FreeBSD 4.7-STABLE.
ISTR that some of the changes between 2.05a and 2.05b had something to
do with globbing, but it is not immediately obvious from the 2.05b
change log, unless this is part of the internal malloc() overhaul.

Can you test this with bash-2.05b?

G'luck,
Peter

--
Peter Pentchev roam (at) ringlet (dot) net [email concealed] roam (at) sbnd (dot) net [email concealed] roam (at) FreeBSD (dot) org [email concealed]
PGP key: http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint FDBA FD79 C26F 3C51 C95E DF9E ED18 B68D 1619 4553
.siht ekil ti gnidaer eb d'uoy ,werbeH ni erew ecnetnes siht fI

[ reply ]
RE: Bash Blues. Feb 13 2003 09:44PM
Adam Gilmore (vuln optusnet com au)
Re: Bash Blues. Feb 13 2003 05:34PM
Roland Postle (mail blazde co uk) (1 replies)
glibc glob_filename() recurse call stack overflow (Re[2]: Bash Blues) Feb 15 2003 06:54AM
3APA3A (3APA3A SECURITY NNOV RU) (1 replies)
Re: glibc glob_filename() recurse call stack overflow (Re[2]: Bash Blues) Feb 15 2003 09:30PM
Vladamir Shmirnov (red_vigil yahoo com) (2 replies)
Re: glibc glob_filename() recurse call stack overflow (Re[2]: Bash Blues) Feb 16 2003 10:19AM
spacewalker (spacewalker altern org)
Re: glibc glob_filename() recurse call stack overflow (Re[2]: Bash Blues) Feb 16 2003 01:54AM
Roland Postle (mail blazde co uk)
Re: Bash Blues. Feb 13 2003 05:29PM
TerraTrans Security (NimaDeus pandora be) (1 replies)
A different bash blues Feb 15 2003 01:48AM
admin badger sytes net (1 replies)
RE: A different bash blues Feb 16 2003 02:28PM
Adam Gilmore (vuln optusnet com au)
Re: Bash Blues. Feb 13 2003 05:08PM
Andrew Walkingshaw (andrew-bugtraq lexical org uk) (2 replies)
Re: Bash Blues. Feb 14 2003 05:31AM
Kurt Seifried (kurt seifried org)
Re: Bash Blues. Feb 14 2003 12:37AM
Dack (bugtraq42 hotpop com)







 

Privacy Statement
Copyright 2009, SecurityFocus