3 ms·
The better way to check for buffer overflow here is "((unsigned T)i < n)". But the "(i >= 0 && i < n)" way that I used in this example - I have seen many times
by jpegqs 6y ago
The better way to check for buffer overflow here is "((unsigned T)i < n)".
But the "(i >= 0 && i < n)" way that I used in this example - I have seen many times.
So hackers can scan open source software compiled with GCC for such issue and can exploit this vulnerability, since GCC developers will not fix it.