Re: Potential Denial of Service Vulnerability in embedded commands - Bash version 4.4.12(1) - Release

2017-11-07 Thread Alex Nichols
oting that the Kali example should have been able to have allocated more than enough memory to hold the 2GB file since it was able to allocate up to 4296613888 bytes of heap memory when it crashed. On Tue, Nov 7, 2017 at 2:21 PM, Eduardo Bustamante wrote: > On Tue, Nov 7, 2017 at 5:58 AM, Alex

Potential Denial of Service Vulnerability in embedded commands - Bash version 4.4.12(1) - Release

2017-11-07 Thread Alex Nichols
Hi All, I’m an Ethical Hacking student at Coventry university and while doing some exploit development on my Linux boxes I stumbled across a bug in the bash 4.4.12(1) - release. In order to trigger the bug I executed the command *`*cat sploit.buf*`* where sploit.buf is a just over 2GB file of ‘