[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <452AA410.9090509@gmail.com>
Date: Mon, 09 Oct 2006 21:33:36 +0200
From: "the.soylent" <the.soylent@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: Kmail <= 1.9.1 (latest) DOS
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
SecuriTeam Expert schrieb:
> What drivers do you use for X ? (my guess nvidia).
yes, nvidia ;)
not only ff or gedit crash the x-server, also opening it with epiphany
(0.5.1-1ubuntu1) does the job ;)
ok, i tested a bit more around:
i open the link on a fresh installed & full patched ubuntu 6.06, 32 and
64 bit version..(also nvidia-graphic) same effect:
- -32bit-
Linux amd3800-64 2.6.15-27-amd64-generic
X: 7.0.0-0ubuntu45
gnome: 1:2.12.2.3
nvidia-kernel-common: 20051028+1
- -64bit-
Linux amd3800 2.6.15-27-k7
gnome, x, .. : same as above
firefox -> crash
gedit -> crash
epiphany -> crash
interesting part:
when the x server previously runs on tty7, it runs after crash at tty8
and vice versa.
at the "crashed tty" is displayed the following (64bit):
*** glibc detected *** free(): invalid next size (normal):
0x0000000001094d50 *** glibc detected *** double free or corruption
(!prev) 0x00000000010661e0 ***
same messages on the 32bit-system (with shorter memory-addresses)
tested it also on a debian-sarge-system (kde+gnome) and pleased someone
with gentoo (fluxbox) to test it: no effect
maybe ubuntu-specific?
hope this helps,
/soylent
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFFKqQPY86qEhC92cgRAvIOAJ44GQKNQbfIEdLoWZtw654U6JAacwCeOpb5
gUv/8WCUEJ+ZShG6gdY/psk=
=KT1N
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists