Invalid memory access / read stack overflow when reading config with zero bytes

Hanno Böck hanno at hboeck.de
Mon Mar 30 09:36:02 AEDT 2015


On Mon, 30 Mar 2015 09:19:02 +1100 (AEDT)
Damien Miller <djm at mindrot.org> wrote:

> What version of OpenSSH is this?

6.8 portable on Linux.

> Also, when reporting fuzzer-derived problems it really helps to
> include the test-case.

The "test case" is a one byte file containing a zero byte. But here it
is :-)

-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno at hboeck.de
GPG: BBB51E42
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.mindrot.org/pipermail/openssh-unix-dev/attachments/20150330/9bfa2215/attachment.bin>


More information about the openssh-unix-dev mailing list