North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Potentially dangerous Pentium bug disc

  • From: Greg A. Woods
  • Date: Wed Nov 12 13:54:00 1997

[ On Wed, November 12, 1997 at 10:15 (PST), Randy Bush wrote: ]
> Subject: Re: Potentially dangerous Pentium bug disc
>
> gated does not have that illegal instruction sequence in it.  compilers
> don't generate it.  httpd does not have the sequence.

No, httpd certianly should not contain the illegal instruction within
itself, but being the complex critter it is it we find that it commonly
executes other programs on behalf of the remote user.  You might want to
peek at:  CERT Advisory CA-97.25 - CGI_metachar.

There's no clear exploit implied that involves the CPU hang bug (unlike
the corresponding browser bug that's already been discussed), but it
clearly identifies some very real risks that could lead to such exploits.

-- 
							Greg A. Woods

+1 416 443-1734      VE3TCP      <[email protected]>      <robohack!woods>
Planix, Inc. <[email protected]>; Secrets of the Weird <[email protected]>