Re: SSH deja vu

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




 I don't know about any teso exploit, but what I want to mention is
that I rememeber studying this problem myself and I've found
that the crc32 bug doesn't manifest under operating systems that
return NULL on realloc(ptr, 0);
 So if the exploit is based on the fact that realloc(ptr, 0) will
NOT return NULL, Linux & W2k (systems I have access on) were never
actually vulnerable.

 The Linux realloc manual says :
 "realloc() returns a pointer to the newly allocated memory, which is
 suitably aligned  for  any  kind  of variable  and  may  be  different
 from ptr, or NULL if the request fails or if size was equal to 0.

CONFORMING TO
       ANSI-C
"

Regards,
Luci



[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux