Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: CAL-20070912-1 Multiple vendor produce handling AVI file vulnerabilities Sep 21 2007 06:47PM
Florian Weimer (fw deneb enyo de)
* Code Audit Labs:

> that's funny, the above code still can be bypassed because of
> incorrect check order.
>
> and example code
> calloc(0x10000001, 0x10);
>
> it will return NULL in winxp or gligc 2.5
> it will return 0x10 sizes heap in glibc <2.5(maybe prior) or
> win2000 sp...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus