BugTraq
simple buffer overflow in gedit Nov 23 2003 02:37PM
Andreas Constantinides (MegaHz) (megahz megahz org) (1 replies)
Re: simple buffer overflow in gedit Nov 24 2003 05:37PM
Matthias Buelow (mkb mukappabeta de)
Andreas Constantinides (MegaHz) wrote:

> Hello,
> I discover a strange but simple buffer overflow in gedit.
> I am using RH9,
> to demostrate the buffer here is a simple file buffer generator:

[writes 9999999 A's to stdout]

> # g++ -o buffer buffer.c
> # ./buffer > lala
> # gedit lala
> Segmentation fault
> #

your process most likely gets killed because of a resource limit. check
ulimit. gedit grows to over 300mb rss with that file as input and seems
to stay occupied with running whatever suboptimal algorithms it has for
that special case. clearly it's not the proper tool to operate on such
files. it doesn't crash, however, at least not the current version 2.4.0.

--
no signature is a good signature

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus