BugTraq
PointGuard: It's not the Size of the Buffer, it's the Address of the Pointer Aug 13 2003 11:45PM
Crispin Cowan (crispin immunix com) (1 replies)
Re: PointGuard: It's not the Size of the Buffer, it's the Address of the Pointer Aug 15 2003 01:43PM
Florian Weimer (fw deneb enyo de) (1 replies)
Crispin Cowan <crispin (at) immunix (dot) com [email concealed]> writes:

> Thanks to Snax and the Shmoo for a better tag line: It's not the Size
> of the Buffer, it's the Address of the Pointer

This is not true. There are buffer overflow exploits which do not
modify pointers, but other objects. The most prominent example is
probably the "c c c c c..." exploit for the Solaris /bin/login
vulnerability.

[ reply ]
Re: PointGuard: It's not the Size of the Buffer, it's the Address of the Pointer Aug 15 2003 06:00PM
Crispin Cowan (crispin immunix com)


 

Privacy Statement
Copyright 2010, SecurityFocus