3 ms·
Small security hole in this: since i0/i1/i2 are signed ints, i0 % 8 etc can be negative, and thus allow writing in the 7 bytes before r[], quite possibly leadin
by zwegner 11y ago
Small security hole in this: since i0/i1/i2 are signed ints, i0 % 8 etc can be negative, and thus allow writing in the 7 bytes before r[], quite possibly leading to a stack smashing attack. So you probably don't want to run this in production :)
- wkoszek 11y agoYou're right: I didn't design it to be run with UID 0. However I fixed the issue and gave you the credit: https://github.com/wkoszek/cpu60/commit/672711f3e06bba424b98263655ca923eaf587a1b https://github.com/wkoszek/cpu60/commit/672711f3e06bba424b98...