Re: [remote] [control] NASM 0.98.38 error() overflows buff[]
Stanislav Karchebny <[email protected]> Wed, 15 Dec 2004 19:23:57 +0500
| Newsgroups | gmane.comp.lang.nasm.devel,gmane.comp.security.software |
|---|---|
| Organization | eXQuance |
| Message-ID | <[email protected]> |
--nextPart2033583.zqHpel46YV Content-Type: text/plain; charset="koi8-r" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline On Wednesday 15 December 2004 13:20, D. J. Bernstein wrote: > Here's the bug: In preproc.c, error() uses an unprotected vsprintf() to > copy data into a 1024-byte buff[] array. > > ---D. J. Bernstein, Associate Professor, Department of Mathematics, > Statistics, and Computer Science, University of Illinois at Chicago Thank you D.J.! We will fix it asap. =2D-=20 keep in touch. berkus. Roey on #kde-devel: when I hear best of breed I tune out--it's too much a=20 buzzword. What I carry between my legs is best of breed. And like KDE, just= =20 because it's less visible doesn't mean it gets less usage. --nextPart2033583.zqHpel46YV Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQBBwEkD8v4MNv5cuDkRAh7lAJ4sgFct1sa/KOnJtqh2lFTEdOgVZACeM5si r5kT0fAcfkwvul6v1UyKUto= =x4Qm -----END PGP SIGNATURE----- --nextPart2033583.zqHpel46YV-- ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://productguide.itmanagersjournal.com/