[MPICH] stdin buffer overflow problem?

Rajeev Thakur thakur at mcs.anl.gov
Tue Feb 26 20:23:59 CST 2008


> In that case, can you tell me (1) how large is "large" [it 
> looks like a few K will do it!], 

Yes, a few K of stdin could be difficult for mpd to handle

> and (2) is there really a 
> security problem when MPD is run as root?

It might be possible to crash MPD with floods of stdin data. But the OS
should be able to prevent an application (MPD) from causing the machine to
crash.

Rajeev


> 
> 		Ben
> 
> Rajeev Thakur wrote:
> > Yes, the MPD process manager doesn't handle large input files via 
> > stdin very well. In such cases, you will need to read from 
> a file as you have.
> > 
> > Rajeev
> > 
> >> -----Original Message-----
> 
> >> This looks like a serious security problem.  I am running mpd as 
> >> root, with MPD_USE_ROOT_MPD=1.  So this, I think, is how a buffer 
> >> overflow can crash the entire node.
> 
> 
> -- 
> Prof. Benjamin Svetitsky           Phone:  +972-3-640 8870
> School of Physics and Astronomy    Fax:    +972-3-640 7932
> Tel Aviv University                E-mail: bqs at julian.tau.ac.il
> 69978 Tel Aviv, Israel             WWW:    
> http://julian.tau.ac.il/~bqs
> 
> 




More information about the mpich-discuss mailing list