Re: binutils buffer overflow

2005-06-02 Thread Jeffrey Lim
On 02 Jun 2005 13:20:32 +0200, Artur Grabowski <[EMAIL PROTECTED]> wrote: > "Alexey E. Suslikov" <[EMAIL PROTECTED]> writes: > seems that it's more than just 'strings' though - see http://bugs.gentoo.org/show_bug.cgi?id=91398#c0. Supposedly even gdb is affected? Or is it only affected because it u

Re: binutils buffer overflow

2005-06-02 Thread Artur Grabowski
"Alexey E. Suslikov" <[EMAIL PROTECTED]> writes: > binutils < 2.16-r1 are vulnerable > > http://www.gentoo.org/security/en/glsa/glsa-200506-01.xml So? What's the attack vector? You give a random executable to a sysadmin and ask him to not run it, but instead do a "strings" on it? And ask him to