North American Network Operators Group Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical Re: Potentially dangerous Pentium bug disc
[ On Wed, November 12, 1997 at 10:15 (PST), Randy Bush wrote: ] > Subject: Re: Potentially dangerous Pentium bug disc > > gated does not have that illegal instruction sequence in it. compilers > don't generate it. httpd does not have the sequence. No, httpd certianly should not contain the illegal instruction within itself, but being the complex critter it is it we find that it commonly executes other programs on behalf of the remote user. You might want to peek at: CERT Advisory CA-97.25 - CGI_metachar. There's no clear exploit implied that involves the CPU hang bug (unlike the corresponding browser bug that's already been discussed), but it clearly identifies some very real risks that could lead to such exploits. -- Greg A. Woods +1 416 443-1734 VE3TCP <[email protected]> <robohack!woods> Planix, Inc. <[email protected]>; Secrets of the Weird <[email protected]>
|