Hi,
Quoting StyX ([EMAIL PROTECTED]):
> styx@SuxOS-devel:~$ man -l %n%n%n%n
> man: Segmentation fault
> styx@SuxOS-devel:~$
>
> This was on my Debian 2.2 potato system (It doesn't dump core though).
Just for the record:
on a lot of systems (including Debian), 'man' is not suid/sgid anything, and
this doesn't impose a security problem.
I don't know about Suse/Redhat/others.
Greets,
Robert
--
Linux Generation
- Re: SuSe / Debian man package format string vulnerab... Roman Drahtmueller
- Re: SuSe / Debian man package format string vulnerab... Tomasz Kuźniar
- m4 format string vulnerability [was: Re: SuSe /... Mike Gerber
- Re: m4 format string vulnerability [was: Re... Ivo van Poorten
- Re: m4 format string vulnerability Jarno Huuskonen
- Re: SuSe / Debian man package format string vulnerab... StyX
- Re: SuSe / Debian man package format string vul... Martin Schulze
- Re: SuSe / Debian man package format string... Jose Nazario
- Re: SuSe / Debian man package format st... Nate Eldredge
- Re: SuSe / Debian man package format string... Robert Bihlmeyer
- Re: SuSe / Debian man package format string vul... Robert van der Meulen
- Re: SuSe / Debian man package format string... Valdis Kletnieks
- Re: SuSe / Debian man package format string... Ethan Benson
- Re: SuSe / Debian man package format string... John
- Re: SuSe / Debian man package format st... Megyer Ur
- Re: SuSe / Debian man package forma... Foldi Tamas
- Re: SuSe / Debian man package format st... Andreas Ferber
- Re: SuSe / Debian man package format st... Graham Hughes
- Re: SuSe / Debian man package format st... Matt Zimmerman
- Re: SuSe / Debian man package format string... Mate Wierdl
- Re: SuSe / Debian man package format string... Roman Drahtmueller
