Re: bin/64150: [PATCH] ls(1) coredumps when started via execve(2

看板FB_security作者時間22年前 (2004/03/16 04:25), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串10/12 (看更多)
On Fri, Mar 12, 2004 at 08:29:52PM +0100, Marc Bevand wrote: > On 12 Mar 2004, Ruslan Ermilov wrote: > | On Fri, Mar 12, 2004 at 11:07:25AM -0500, Tom Rhodes wrote: > | > > | > Will it 'break' anything? > | > | Sure it will, the question is should we care about something that's > | already broken. ;) > > It will break almost all shellcodes trying to be the shorter ones > (as they pass NULL for argv and envp). So we can view it as a small > security improvement (just kidding). When I tested my patches (over 2 years ago), I didn't trigger any compilation, nor any runtime problems... Marc _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #10LX5L00 (FB_security)
討論串 (同標題文章)
完整討論串 (本文為第 10 之 12 篇):
文章代碼(AID): #10LX5L00 (FB_security)