CVE-2130-5680, HylaFAX+ heap overflow, unchecked network traffic.

2013-09-30 Thread Dennis Jenkins
t Homepage: http://hylafax.sourceforge.net/ Vulnerability: CWE-120: Classic buffer overflow from unchecked network traffic, resulting in heap corruption. Vulnerability Discoverer: Dennis Jenkins (dennis.jenkins.75 _at_ gmail.com) CVE reference: CVE-2130-5680, 2013-09-03 Solution Status: Fixed

Re: Windows MS-DOS Device Name DoS vulnerabilities

2001-07-09 Thread Dennis Jenkins
Since DOS devices exist in every directory (as first explained to me in the book 'Undocumented Dos'), we had a trick for testing for the presence of a directory in a batch file. The test went like this: if exist C:\DIRECTORY\MOREDIRS\NUL then . Because 'NUL' existed in every

Re: Windows MS-DOS Device Name DoS vulnerabilities

2001-07-09 Thread Dennis Jenkins
Pavel Kankovsky wrote: > > On Fri, 6 Jul 2001, 3APA3A wrote: > > > ... and the problem is definitely in software, not in operation > > system, because operation system behaves exactly as expected and > > documented. > > But it is still OS's problem when the specification / documentation it >