2 ms·
Why isn't static analysis or "sanitizers" finding this?
by TwoBit 11y ago
Why isn't static analysis or "sanitizers" finding this?
- viraptor 11y agoGood question. I'd expect static analysis to find the leak automatically - it's pretty obvious. The off by one however is behind many branches and only detectable if you know the buffer size at the call site... I'd be surprised if it triggered any scanning tool. As a general answer though: static analysis will give you better answers if you write your code in a clean and well structured way. If you goto from a branch from a branch from a (potentially infinite) for-loop from a (not counting) while-loop - good luck :) OpenSSL's OBJ_/BN_/... functions seem to strive for complexity.
- fulafel 11y agoThey have major limitations. C is unsafe even with all the mitigation tools in the world and in the end they're only going to catch the low-hanging fruit.