Subject: Re: Very interesting traceroute flaw (fwd)
To: None <abs@purplei.com>
From: Hubert Feyrer <hubert.feyrer@informatik.fh-regensburg.de>
List: tech-security
Date: 09/29/2000 14:11:54
  by mail.netbsd.org with SMTP; 29 Sep 2000 12:09:54 -0000
	by rfhs8012.fh-regensburg.de (8.10.1/8.10.1) with ESMTP id e8TC95002236;
	Fri, 29 Sep 2000 14:09:05 +0200 (MET DST)
Date: Fri, 29 Sep 2000 14:11:54 +0200 (MET DST)
From: Hubert Feyrer <hubert.feyrer@informatik.fh-regensburg.de>
To: abs@purplei.com
cc: tech-security@netbsd.org
Subject: Re: Very interesting traceroute flaw (fwd)
In-Reply-To: <Pine.NEB.4.21.0009291304070.289-100000@localhost>
Message-ID: <Pine.GSO.4.21.0009291411220.24129-100000@rfhpc8320.fh-regensburg.de>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII

On Fri, 29 Sep 2000 abs@purplei.com wrote:
> 	Looks like our traceroute uses strsave on hi->name in traceroute.c
> 	and then later frees it - could be an issue?

noon% traceroute -g 1 -g 1
traceroute in free(): warning: page is already free.
Version 1.4a5
Usage: traceroute [-dDFPIlnrvx] [-g gateway] [-i iface] [-f first_ttl] [-m max_ttl]
        [ -p port] [-q nqueries] [-s src_addr] [-t tos] [-w waittime]
        host [packetlen]

That's a bit older 1.5_ALPHA2.


 - Hubert

-- 
Hubert Feyrer <hubert.feyrer@informatik.fh-regensburg.de>