Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 6 Oct 1999 07:43:13 +1000
From:      Peter Jeremy <peter.jeremy@alcatel.com.au>
To:        Ruslan Ermilov <ru@ucb.crimea.ua>
Cc:        gnats-admin@FreeBSD.ORG, freebsd-bugs@FreeBSD.ORG
Subject:   Re: bin/14069: Buffer overflow in mail(1)
Message-ID:  <99Oct6.073949est.40331@border.alcanet.com.au>
In-Reply-To: <19991005102521.A27498@relay.ucb.crimea.ua>
References:  <99Oct1.143612est.40354@border.alcanet.com.au> <19991001182849.A28871@relay.ucb.crimea.ua> <99Oct5.094616est.40329@border.alcanet.com.au> <19991005102521.A27498@relay.ucb.crimea.ua>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Hi Ruslan,

On 1999-Oct-05 17:25:21 +1000, Ruslan Ermilov wrote:
>On Tue, Oct 05, 1999 at 09:49:37AM +1000, Peter Jeremy wrote:
>> On 1999-Oct-10 01:28:49 +1000, Ruslan Ermilov wrote:
>> >Could you please gzip and send me your test mbox?
>> 
>> See attached.  (I was worried about the test being corrupted in
>> transit, but the bug reporting rules discourage non-text attachments).
>> 
>Can't reproduce, see attached.

I've found that the test file I used does not trigger the problem when
mail is compiled without `-O'.  Increasing the number of `To:' addresses
in the test file _does_ trigger the problem.  I've enclosed a new
test file.  Let me know if this still doesn't work for you and I'll
send you my binary and core.

Note that David Rivers also pointed out that there's an off-by-1
bug in the alloca (since I forgot the terminating NUL).

Peter
-- 
Peter Jeremy (VK2PJ)                    peter.jeremy@alcatel.com.au
Alcatel Australia Limited
41 Mandible St                          Phone: +61 2 9690 5019
ALEXANDRIA  NSW  2015                   Fax:   +61 2 9690 5982

[-- Attachment #2 --]
n7jeremyp.3YWyc3gAg7`E>$!P}Ivu3MVh`:K/<pS5>KX?ZQO׏t=}M99C4.u0_5__pG>;į?^'(]_9G^;tj,)HT*ϥO&Ị4Z7s)}	R|zzB
!R!Z&%wuîz:ݏSv-MWw5WuPqpgL9:\ٝ]vR*gK/O.qkt7wlȍ
,XcAkJr,P%@q3?>|c_VTn[۞ضZ9}Sjچ[٪سE!QThv6;vk76+wOwnt<e2,g.˓va6;S;1ztT*v3.>|.݌mf%>K~+>Ȣyed虮mZia`j#
b?GHœx4|9H&h_eQ_O#T[\ٜLp47I@bnڬ,ā،aJ7-5t{tGuK7u#u]U}g
'}}S{NV赆^ꅞ5MMGz%P\STx7ꨶj)TQ7uV'uAUjRUQ	=J-UPs+XeoR
%$˞Hh֒Mِu	5Y\YAdr'S[I r%r2LNDB$r$0AAܵXEOtAtD[D
Q5Uq.,N( "Nb+6 ;K0A,fb*& "{p$3Pr1>E[<h*=xg~~䇀ywREy|ŗ|O8D||tG|Q2Ǻ:>Ϭj.;=ˀnKٖm%lV,X،g"6f#6d4bڧAvi(4=٠uZU
z)dw`GS[ABtE@`LgtJaB#: s?A
N[aF{VCc}S7"܄Ip.E8ppFQ{!@H&- P'HT\ș'r$)ؐɊK sށ	Ɉ2{:8Z1˙6n&㠆/NG`=yron*	^%^9Op7Q{A` ^FilT(?:o(Cj88|y)Ԓ<&ca{گtWkWhc?tM1ZqjG
t퍨Pwk,s坭{Bvoh&7߯T|r&%5Ny9AMv,Ζ|mi|O&J.EˮGo]?F

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?99Oct6.073949est.40331>