2 ms·
The long history of exploitable buffer overflows in C programs is something to keep in mind when people hyperventilate about how recent vulnerabilities in a pop
by bithive123 14y ago
The long history of exploitable buffer overflows in C programs is something to keep in mind when people hyperventilate about how recent vulnerabilities in a popular framework reflect on the security of the language ecosystem as a whole.
- tedunangst 14y agoIt's been a long time since somebody tried to convince me that a buffer overflow was an intentional feature of the program they were developing...
- sanderjd 14y agoAssuming you and your parent are both coyly referring to the recent YAML parsing related Ruby and Rails vulnerabilities, I think the analogy is better than you realize. Raw strcat is to the built-in YAML parser as strncat is to the various whitelist-based YAML fixes[1]. Both strcat and the YAML parser work as intended, but should never be exposed to data controlled by an external source. Buffer overflows aren't intentional, but uses of strcat are, even when they are wrong. 1. https://github.com/dtao/safe_yaml https://github.com/dtao/safe_yaml