Re: Stack Smashing and no-exec

Alan Cox (alan@lxorguk.ukuu.org.uk)
Fri, 7 Aug 1998 20:02:09 +0100 (BST)


> I understand that this could happen. But have you "compromised the
> security of the system?" I really don't think you have. Those are
> still major problems though, I will admit that.

You have compromised the security of that user account. If the OS is
functioning properly then it will have done its work and the attacker can do
no harm to other users.

Any program that touches untrusted data must be securely written - image
viewers and email clients are some of the worst culprits and easiest
targets

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.altern.org/andrebalsa/doc/lkml-faq.html