Re: [Patch] Fix buffer overflow in kill utility

2005-02-26 Thread Christopher Faylor
On Sat, Feb 26, 2005 at 06:43:08PM -0800, Brian Dessent wrote: > >In kill.cc there exists the possibility to overflow the "char buf[80]" >array by supplying malformed command line arguments. > >An attacker could use this to overwrite the return value on the stack >and execute arbitrary code, but th

[Patch] Fix buffer overflow in kill utility

2005-02-26 Thread Brian Dessent
In kill.cc there exists the possibility to overflow the "char buf[80]" array by supplying malformed command line arguments. An attacker could use this to overwrite the return value on the stack and execute arbitrary code, but the amount of space available on the stack for shellcode is approx 108