Re: PointGuard: It's not the Size of the Buffer, it's the Address of the Pointer

From: Florian Weimer (fwat_private)
Date: Fri Aug 15 2003 - 06:43:42 PDT

  • Next message: Jane Smith: "Re: wu-ftpd fb_realpath() off-by-one bug"

    Crispin Cowan <crispinat_private> writes:
    
    > Thanks to Snax and the Shmoo for a better tag line: It's not the Size
    > of the Buffer, it's the Address of the Pointer
    
    This is not true.  There are buffer overflow exploits which do not
    modify pointers, but other objects.  The most prominent example is
    probably the "c c c c c..." exploit for the Solaris /bin/login
    vulnerability.
    



    This archive was generated by hypermail 2b30 : Fri Aug 15 2003 - 10:18:13 PDT