POV-Ray : Newsgroups : povray.general : Security Issues in Povray? : Security Issues in Povray? Server Time
19 Nov 2024 05:22:39 EST (-0500)
  Security Issues in Povray?  
From: ncryptor
Date: 22 Apr 2002 13:26:26
Message: <pan.2002.04.22.20.26.18.339516.6785@me.localdomain>
I have been studying the Linux source code of POV-Ray (version that is
posted on web site).
It may be possible to obtain shell or other access to the host's computer by
exploiting bugs in pov's handling of command line parameters. Try this:
give pov a very long command line parameter and it crashes with a
segmentation fault. I am trying to see if this is exploitable, it
probably is.

A possible exploit of this could be to gain access to a computer
running pov as part of a render farm. The command line for pov depends on
the information sent from the server to the client farmer, so an
exploiter could spoof information and gain access to the user's computer.

The problematic file is optin.c


Post a reply to this message

Copyright 2003-2023 Persistence of Vision Raytracer Pty. Ltd.