Re: [Lit.] Buffer overruns

From: infobahn (infobahn_at_btinternet.com)
Date: 01/31/05


Date: Mon, 31 Jan 2005 11:56:55 +0000 (UTC)

Paul Rubin wrote:
>
> infobahn <infobahn@btinternet.com> writes:
> > I mean that buffer overruns represent only a small fraction of the
> > bugs likely to be present in a buggy program.
>
> It's been the cause of a huge number of exploits that lead to total
> attacker takeover of the program. Most other types of bugs have less
> severe consequences.

What evidence have you to support that claim? Buffer overruns leading
to machine "capture" are dramatic, but what makes you think other bugs
don't also lead to serious consequences?



Relevant Pages

  • Re: perfomance vs. key size
    ... > There are buffer overruns even in various versions of MS CryptoAPI ... > exploitable bugs and increases the probability that any bugs are ... http://www.garlic.com/~lynn/2002l.html#42 Thirty Years Later: Lessons from the Multics Security Evaluation ...
    (sci.crypt)
  • Re: [Lit.] Buffer overruns
    ... I thought we wanted, ideally, a program with no bugs. ... >>with eliminating buffer overruns. ... > would be pointless if programmers would only follow your discipline. ... > Is the same true when you restrict attention to exploitable security ...
    (sci.crypt)
  • Re: Linux Xorg Is Riddled With Security Bugs. Its a Hackers Dream!
    ... Nate Bananarama Latwanda III Jr. ... The bugs are scattered across the whole ... > include endless loops, buffer overruns, buffer underruns, code ... > applications that use libXpm to process data from untrusted sources. ...
    (alt.os.linux.suse)
  • Re: Linux Xorg Is Riddled With Security Bugs. Its a Hackers Dream!
    ... Nate Bananarama Latwanda III Jr. ... The bugs are scattered across the whole ... > include endless loops, buffer overruns, buffer underruns, code ... > applications that use libXpm to process data from untrusted sources. ...
    (alt.os.linux)
  • Re: [Lit.] Buffer overruns
    ... these buffer overruns don't appear magically from nowhere. ... I'm most concerned about inadvertent bugs (buffer overruns that were ... the N-person code review stage. ... Code reviews are good, but I don't know ...
    (sci.crypt)