3 ms·
I can think of two reasons. The first is what they describe here: as an attack. It's like why would anyone ever overflow a buffer with shellcode. The second i
by scottlamb 4mo ago
I can think of two reasons.
The first is what they describe here: as an attack. It's like why would anyone ever overflow a buffer with shellcode.
The second is that they are implementing a spec that requires appending a varint length-prefixed field to a buffer but don't really care about the space optimization, don't know the field's length when they start appending it, and don't want to put the field into a second, temporary buffer or slide it down into place. https://github.com/FFmpeg/FFmpeg/blob/468a743af1653a08f47081aa0a18dc6dacff543a/libavformat/movenc.c#L694-L701 https://github.com/FFmpeg/FFmpeg/blob/468a743af1653a08f47081... vs say my own code which does the slide: https://github.com/scottlamb/retina/blob/6972ac4261ce7bf5b585da9051606c7b5c0ab82c/src/codec/mod.rs#L88-L99 https://github.com/scottlamb/retina/blob/6972ac4261ce7bf5b58...
- wahern 4mo agoThird is by accident, including by buggy code, and the permissiveness means it's easier for bugs to go unnoticed. See, e.g., https://news.ycombinator.com/item?id=48327115 https://news.ycombinator.com/item?id=48327115