Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: rumen_yotov@×××.bg
Cc: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] pciutils / lspci -vv buffer overflow
Date: Mon, 26 Jul 2004 03:34:46
Message-Id: 1090812847.24802.10.camel@simple
In Reply to: Re: [gentoo-hardened] pciutils / lspci -vv buffer overflow by Rumen Yotov
1 Rimer can you verify the fix please?
2
3 On Sun, 2004-07-25 at 23:27, Rumen Yotov wrote:
4 > On пн, 2004-07-26 at 03:56, Pascal de Bruijn wrote:
5 > > Hi,
6 > >
7 > > I have investigated the lspci -vv buffer overflow... This only seemed to
8 > > occur on certain installations, this should be on systems which have
9 > > AGPx1 and AGPx2 and AGPx4 support.
10 > >
11 > > For more information:
12 > > http://members.home.nl/keizerflipje/hacks/lspci/lspci.txt
13 > > http://members.home.nl/keizerflipje/hacks/lspci/lspci.diff
14 > >
15 > > I really like to get this verified...
16 > >
17 > > Greets,
18 > > Pascal de Bruijn
19 > >
20 > > --
21 > > gentoo-hardened@g.o mailing list
22 > >
23 > Hi,
24 > Can confirm lspci -vv buffer overflow on K7VM2 mobo with following
25 > message:
26 > ...CUT...
27 > 0000:00:00.0 Host bridge: VIA Technologies, Inc. VT8375 [KM266/KL266]
28 > Host Bridge
29 > Subsystem: Unknown device 1849:3156
30 > Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop-
31 > ParErr- Stepping- SERR- FastB2B-
32 > Status: Cap+ 66Mhz+ UDF- FastB2B- ParErr- DEVSEL=medium >TAbort-
33 > <TAbort- <MAbort+ >SERR- <PERR-
34 > Latency: 8
35 > Region 0: Memory at e0000000 (32-bit, prefetchable)
36 > Capabilities: [a0] AGP version 2.0
37 > Status: RQ=32 Iso- ArqSz=0 Cal=0 SBA+ ITACoh- GART64-
38 > HTrans- 64bit- FW+ AGP3-
39 > Rate=x1,x2,x4
40 > Command: RQ=1 ArqSz=0 Cal=0 SBA- AGP- GART64- 64bit- FW-
41 > Rate=<none>
42 > lspci: stack smashing attack in function show_agp()
43 > ................................^^^^^^^^^^^^^^^^^^^
44 > Aborted
45 > ...END CUT...
46 > Rumen
47 --
48 Ned Ludd <solar@g.o>
49 Gentoo (hardened,security,infrastructure,embedded,toolchain) Developer

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] pciutils / lspci -vv buffer overflow Rumen Yotov <rumen_yotov@×××.bg>