lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <1068406242.17914.15.camel@megahz> Date: 09 Nov 2003 21:30:42 +0200 From: "Andreas Constantinides (MegaHz)" <megahz@...ahz.org> To: bugtraq@...urityfocus.com Subject: buffer overflow in unace (linux extractor for .ace files) Hello, I have discover a realy simple buffer overflow in unace(www.winace.com) command. normally if you put a wrong filename: [root@...ahz root]# ./unace e aa.ace UNACE v2.2 Copyright by ACE Compression Software May 9 2002 10:59:42 Error: No such archive found: /root/aa.ace [root@...ahz root]# ==================================================================================== the buffer overflow [root@...ahz root]# ./unace e aaaaaa(a*600).ace UNACE v2.2 Copyright by ACE Compression Software May 9 2002 10:59:42 Segmentation fault [root@...ahz root]# ==================================================================================== winace was contacted about this. MegaHz www.megahz.org www.cyhackportal.com
Powered by blists - more mailing lists