Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 5 Sep 1999 20:28:22 -0400 (EDT)
From:      "Brian F. Feldman" <green@FreeBSD.org>
To:        Matthew Dillon <dillon@apollo.backplane.com>
Cc:        Garrett Wollman <wollman@khavrinen.lcs.mit.edu>, Nick Hibma <hibma@skylink.it>, FreeBSD -- The Power to Serve <geniusj@free-bsd.org>, Mike Tancsa <mike@sentex.net>, freebsd-security@FreeBSD.org
Subject:   Re: FW: Local DoS in FreeBSD
Message-ID:  <Pine.BSF.4.10.9909052026560.98872-100000@janus.syracuse.net>
In-Reply-To: <199909051637.JAA68325@apollo.backplane.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, 5 Sep 1999, Matthew Dillon wrote:

> 
> :>     old value of ui_sbsize when uip is not NULL.  That may make the
> :>     problem more obvious.
> :
> :I've gdb'd every crash and it's been something like ui_sbsize = 0x1234
> :delta = -0x2000.
> :
> : Brian Fundakowski Feldman           /  "Any sufficiently advanced bug is    \
> 
>     0x1234 could be an indication of a reference to a data structure 
>     which has been freed.

That would be 0xdeadc0de, but it wasn't actually 0x1234. It was something
else somewhat similar. After tracking down the problem k6_mem.c has, I may
look much more into this.

> 	
> 					-Matt
> 					Matthew Dillon 
> 					<dillon@backplane.com>
> 

-- 
 Brian Fundakowski Feldman           /  "Any sufficiently advanced bug is    \
 green@FreeBSD.org                   |   indistinguishable from a feature."  |
     FreeBSD: The Power to Serve!    \        -- Rich Kulawiec               /



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.10.9909052026560.98872-100000>