From: James Courtier-Dutton <James@superbug.co.uk>
To: Bart Oldeman <bartoldeman@gmail.com>
Cc: linux-msdos@vger.kernel.org
Subject: Re: Possible exploit potential in dosemu.
Date: Mon, 23 Oct 2006 16:52:05 +0100 [thread overview]
Message-ID: <453CE525.3030804@superbug.co.uk> (raw)
In-Reply-To: <c3d607cc0610230531m3a0c79ceh19e32293385add79@mail.gmail.com>
Bart Oldeman wrote:
> On 10/19/06, James Courtier-Dutton <James@superbug.co.uk> wrote:
>> The dosemu binary has a rwx stack segment, so this means that
>> instructions can be placed on the stack and executed.
>> This makes it a lot easier to exploit than in the stack was rw-
>>
>> The source objects src/env/video/remap_asm.o and
>> src/env/video/vesabios_pm.o cause this.
>
> There were actually a few other files too, namely the 16bit bios.o and
> vesabios.o files; those were not found by the tool you referred too.
> Not surprisingly because they were linked in a strange way.
>
> It's been corrected in SVN changes 1622 and 1623.
>
> Thanks,
> Bart
Thank you. It is an easy thing to fix, and makes it considerably more
difficult for a cracker to develop and exploit.
prev parent reply other threads:[~2006-10-23 15:52 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-10-19 11:27 Possible exploit potential in dosemu James Courtier-Dutton
2006-10-23 12:31 ` Bart Oldeman
2006-10-23 15:52 ` James Courtier-Dutton [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=453CE525.3030804@superbug.co.uk \
--to=james@superbug.co.uk \
--cc=bartoldeman@gmail.com \
--cc=linux-msdos@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.