Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 103442 - "killall sendmail" stack smashing attack
Summary: "killall sendmail" stack smashing attack
Status: RESOLVED NEEDINFO
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: x86 Linux
: High normal (vote)
Assignee: The Gentoo Linux Hardened Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-08-23 05:57 UTC by M Grundman
Modified: 2007-04-29 14:05 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description M Grundman 2005-08-23 05:57:05 UTC
"killall sendmail" gives always "killall: stack smashing attack in function
kill_all()" 

It seems that killall works well with other names different from sendmail.
This problem occurs with a kernel 2.4.27-openmosix-r2.
With a kernel 2.6.11-hardened-r1 there is no message.

Reproducible: Always
Steps to Reproduce:
1.killall sendmail
2.
3.




Portage 2.0.51.22-r2 (hardened/x86/2.6, gcc-3.3.5-20050130,
glibc-2.3.4.20040808-r1, 2.4.27-openmosix-r2 i686)
=================================================================
System uname: 2.4.27-openmosix-r2 i686 Intel(R) Pentium(R) 4 CPU 1.70GHz
Gentoo Base System version 1.6.13
ccache version 2.3 [enabled]
dev-lang/python:     2.1.3-r1, 2.2.3-r5, 2.3.5
sys-apps/sandbox:    1.2.10
sys-devel/autoconf:  2.13, 2.59-r6
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9, 1.8.5-r3, 1.9.5
sys-devel/binutils:  2.15.92.0.2-r10
sys-devel/libtool:   1.5.18-r1
virtual/os-headers:  2.4.19-r1, 2.6.11-r2
ACCEPT_KEYWORDS="x86"
AUTOCLEAN="yes"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O3 -march=i686 -funroll-loops -pipe"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/2/share/config /usr/kde/3.1/share/config
/usr/kde/3.2/share/config /usr/kde/3.3/env /usr/kde/3.3/share/config
/usr/kde/3.3/shutdown /usr/kde/3.4/env /usr/kde/3.4/share/config
/usr/kde/3.4/shutdown /usr/kde/3/share/config /usr/lib/X11/xkb
/usr/lib/mozilla/defaults/pref /usr/share/config
/usr/share/texmf/dvipdfm/config/ /usr/share/texmf/dvips/config/
/usr/share/texmf/tex/generic/config/ /usr/share/texmf/tex/platex/config/
/usr/share/texmf/xdvi/ /var/bind /var/qmail/control"
CONFIG_PROTECT_MASK="/etc/afs/C /etc/afs/afsws /etc/gconf /etc/terminfo /etc/env.d"
CXXFLAGS="-O3 -march=i686 -funroll-loops -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoconfig buildpkg ccache distlocks sandbox sfperms strict userpriv
usersandbox"
GENTOO_MIRRORS="http://gentoo.inode.at/
http://www.mirrorservice.org/sites/www.ibiblio.org/gentoo/
http://ftp.belnet.be/mirror/rsync.gentoo.org/gentoo/
http://mirror.switch.ch/mirror/gentoo/
http://www.die.unipd.it/pub/Linux/distributions/gentoo-sources/
http://gentoo.blueyonder.co.uk
http://ftp-stud.fht-esslingen.de/pub/Mirrors/gentoo/
http://ftp.easynet.nl/mirror/gentoo/
http://ftp.snt.utwente.nl/pub/os/linux/gentoo
http://ftp.uni-erlangen.de/pub/mirrors/gentoo http://ftp.du.se/pub/os/gentoo
ftp://ftp.belnet.be/mirror/rsync.gentoo.org/gentoo/ http://ftp.lug.ro/gentoo/
http://pandemonium.tiscali.de/pub/gentoo/"
MAKEOPTS="-j1"
PKGDIR="/usr/portage//packages/x86/"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage/"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="3dfx 3dnow 7zip X X509 Xaw3d accounting acl afs amd apache2 arts
artswrappersuid athena authdaemond autofs avascript berkdb bitmap-fonts bonobo
bzip2 caps cdr chroot clamav clearpasswd crypt cups curl derectfb dlloader dlz
doc dvd eds emacs erandom esd evo extensions f77 fam fax fftw firebird firefox
flac font-server foomaticdb footmaticdb foreign-package foreign-sysvinit fortran
gamma gatos gb gcj gd gdbm gif gimpprint ginac glibc-compat20 gmp gnome gnutls
gpm gssapi gstreamer gtk gtk2 guile hardened hardenedphp hdf hdf5 hesiod hpn
i8x0 icc idn imagemagick imap imlib insecure-drivers ipalias jabber java jbig
jikes jpeg kde kerberos krb4 largeterminal latex ldap leim lesstiff libclamav
libedit libgda libwww lids lirc logrotate lufsusermount mad maildir math
matroska mbox mcal md5sum memlimit mikmod milter mimod mmx mng motif mozilla mp3
mpeg mpeg4 mpi msn multilib mupad-noscilab mysql ncurses netcdf nis nls nsplugin
oav odbc ogg opengl openntpd oscar oss pam pam_chroot pam_console pam_timestamp
parse-clocks passfile pcmcia pdf pdflib perl pic pie plotutils png pnp ppds
prelude pwdb python qhull qt quicktime quotas radeon radius rage128 readline rpm
samba sasl scanner sdk sdl session sftp sftplogging sis skey slang slp sndfile
snmp sox speedo speex spell srp sse sse2 ssl streamzap svg svga tcltk tcpd tetex
text tiff transcode truetype truetype-fonts type1 type1-fonts unicode usb
userlocales v4l virus-scan voodoo3 vorbis winbind wmf x86 xattr xemacs xine xml
xml2 xmms xprint xslt xv xvid yahoo yaz zeo zlib video_cards_3dfx
video_cards_gamma video_cards_i810 video_cards_i830 video_cards_matrox
video_cards_rage128 video_cards_radeon video_cards_sis userland_GNU kernel_linux
elibc_glibc"
Unset:  ASFLAGS, CTARGET, LANG, LC_ALL, LDFLAGS, LINGUAS
Comment 1 solar (RETIRED) gentoo-dev 2005-11-25 12:36:12 UTC
I've never seen this and nobody else has reported anything. 
Try relaxing your CFLAGS to the gentoo defaults.