[Bug 339983] [NEW] aircrack airserv-ng crashes with telnet

BUGabundo ubuntu at BUGabundo.net
Sun Mar 8 19:30:59 UTC 2009


Public bug reported:

I started airserv on default port (666) and then connected to it via telnet.
I typed "foo" and it crash  dumped.

if you need me to reproduce with debug symbols, let me know.

$ sudo gdb --args  airserv-ng -d mon0 -v 3
GNU gdb 6.8-debian
Copyright (C) 2008 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu"...

warning: not using untrusted file "/home/bugabundo/.gdbinit"
(no debugging symbols found)
(gdb) r
Starting program: /usr/sbin/airserv-ng -d mon0 -v 3
Opening card mon0
Setting chan 1
Opening sock port 666
Serving mon0 chan 1 on port 666
Connect from 127.0.0.1
PLEN 1869548810 type 102 len 2048
airserv-ng: network.c:138: net_get: Assertion `plen <= *len' failed.

Program received signal SIGABRT, Aborted.
0x00007f9892571fb5 in *__GI_raise (sig=<value optimized out>) at ../nptl/sysdeps/unix/sysv/linux/raise.c:64
64	../nptl/sysdeps/unix/sysv/linux/raise.c: No such file or directory.
	in ../nptl/sysdeps/unix/sysv/linux/raise.c
(gdb) bt full
#0  0x00007f9892571fb5 in *__GI_raise (sig=<value optimized out>) at ../nptl/sysdeps/unix/sysv/linux/raise.c:64
	pid = <value optimized out>
	selftid = <value optimized out>
#1  0x00007f9892573bc3 in *__GI_abort () at abort.c:88
	act = {__sigaction_handler = {sa_handler = 0x7f98928ab860 <_IO_2_1_stderr_>, 
    sa_sigaction = 0x7f98928ab860 <_IO_2_1_stderr_>}, sa_mask = {__val = {140293268012039, 140735788410592, 138, 
      140735788410832, 140293267155558, 206158430232, 140735788410848, 140735788410624, 140293267058808, 206158430256, 
      140735788410872, 14099664, 0, 14099648, 140293270325760, 140735788419574}}, sa_flags = -1838711801, 
  sa_restorer = 0x4084a1 <readdir64 at plt+26793>}
	sigs = {__val = {32, 0 <repeats 15 times>}}
#2  0x00007f989256af09 in *__GI___assert_fail (assertion=0x408527 "plen <= *len", file=0x4084a1 "network.c", line=138, 
    function=0x40865a "net_get") at assert.c:78
	buf = 0xd724d0 ""
	errstr = "Unexpected error.\n"
#3  0x00000000004037d8 in ?? ()
No symbol table info available.
#4  0x0000000000401ed2 in ?? ()
No symbol table info available.
#5  0x00000000004025d2 in ?? ()
No symbol table info available.
#6  0x00007f989255d5a6 in __libc_start_main (main=0x402240 <readdir64 at plt+1608>, argc=5, ubp_av=0x7fff9aacf2a8, 
    init=0x407c60 <readdir64 at plt+24680>, fini=<value optimized out>, rtld_fini=<value optimized out>, 
    stack_end=0x7fff9aacf298) at libc-start.c:220
	result = <value optimized out>
	unwind_buf = {cancel_jmp_buf = {{jmp_buf = {4226144, -6312451520700404337, 4201488, 140735788413600, 0, 0, 
        6312533270769118607, 6292811134324256143}, mask_was_saved = 0}}, priv = {pad = {0x0, 0x0, 0x5, 0x402240}, data = {
      prev = 0x0, cleanup = 0x0, canceltype = 5}}}
	not_first_call = <value optimized out>
#7  0x0000000000401c39 in ?? ()
No symbol table info available.
#8  0x00007fff9aacf298 in ?? ()
---Type <return> to continue, or q <return> to quit---
No symbol table info available.
#9  0x000000000000001c in ?? ()
No symbol table info available.
#10 0x0000000000000005 in ?? ()
No symbol table info available.
#11 0x00007fff9aad09ec in ?? ()
No symbol table info available.
#12 0x00007fff9aad0a01 in ?? ()
No symbol table info available.
#13 0x00007fff9aad0a04 in ?? ()
No symbol table info available.
#14 0x00007fff9aad0a09 in ?? ()
No symbol table info available.
#15 0x00007fff9aad0a0c in ?? ()
No symbol table info available.
#16 0x0000000000000000 in ?? ()
No symbol table info available.
(gdb) 

$ apt-cache policy aircrack-ng  Installed: 1:1.0~rc1-2ubuntu1
jaunty 64bits

 affects ubuntu/aircrack-ng
 status new

** Affects: aircrack-ng (Ubuntu)
     Importance: Undecided
         Status: New

-- 
aircrack airserv-ng crashes with telnet
https://bugs.launchpad.net/bugs/339983
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs at lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs




More information about the universe-bugs mailing list