Re: Linux Kernel 2.2.13 shooting Solaris ADSM server

Alan Cox (alan@lxorguk.ukuu.org.uk)
Wed, 22 Dec 1999 12:02:51 +0000 (GMT)


> > "2.1.131a" or "2.1.131aa" or "2.1.131-preX" or whatever kernel with
> > 8 or more chars will crash the server.
>
> > so, if you used some -pre kernel version, this should be it.
> > edit Makefile and remove the extraversion.
>
> Hmm. I think it might be a good idea to provide snprintf next to sprintf...
> (Or even remove sprintf to make sure everyone uses the safe version)
>
> If any of the kernel-gods wnat this, I'll make a patch for it in the comming
> week.

I'd prefer you post a more detailed note on this to IBM security and to bugtraq.
Its a potentially serious compromise in an important backup tool.

Alan

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/