4 ms·
sprintf buffer overflow in the string library https://github.com/LuaDist/lua/commit/52eff16f51750cf47afaa5ac27a8705a1c580859#diff-5fa4a598e8e43f285d6fb9add1a471
by robert-wallis 13y ago
sprintf buffer overflow in the string library https://github.com/LuaDist/lua/commit/52eff16f51750cf47afaa5ac27a8705a1c580859#diff-5fa4a598e8e43f285d6fb9add1a47182R890 https://github.com/LuaDist/lua/commit/52eff16f51750cf47afaa5...
This library is not included in NetBSD as far as I can tell: http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/modules/lua/?only_with_tag=MAIN http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/modules/lua/?onl...
But it's an indication that it shouldn't be included in a Kernel.
- tedunangst 13y agoYou linked to a 24,000 line diff to point out what exactly?
- robert-wallis 13y agowait for it... the exact section of the code that contains the "sprintf" I mentioned will pop into your screen. Just be patient.
- Sanddancer 13y agoThere were buffer overflows in the Linux kernel in 2012 ( http://www.securityfocus.com/bid/53401 http://www.securityfocus.com/bid/53401 ). Should we not have filesystems in the kernel either?
- pdpi 13y agoWell... No, if you're a proponent of the micro-kernel design.
- robert-wallis 13y agoCertainly the string library, of all places, should be using secure code. I'm sure there are sooo many people running Linux on pre-OSX Mac harddrives formatted with HFS that could be hacked with a buffer overflow. Are you seriously arguing that buffer overflows in the kernel are not a big deal?