Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Results, Not Resolutions
Bruce Schneier and Adam Shostack , SecurityFocus 2002-01-24

A guide to judging Microsoft's security progress.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Results, not Resolutions 2002-01-24
Anonymous
The numerous APIs (have a look at, for example, ntifs.h) that accept null terminated buffers with nary a buffer size argument in sight, or that accept buffers of such buffers (terminated by another null) would seem to invite problems over time. I would argue that when we see alteration in these APIs...

[ more ]  





 

Privacy Statement
Copyright 2007, SecurityFocus