develooper Front page | perl.perl5.porters | Postings from November 2005

Re: Perl PR: "Security holes in Sys::Syslog"

Thread Previous | Thread Next
From:
Gisle Aas
Date:
November 30, 2005 23:43
Subject:
Re: Perl PR: "Security holes in Sys::Syslog"
Message ID:
lrlkz56z60.fsf@caliper.activestate.com
Rafael Garcia-Suarez <rgarciasuarez@mandriva.com> writes:

> 2. Moreover, this kind of vulnerability can be exploited
>    to a buffer overrun in the perl interpreter, by taking
>    advantage of an int<->unsigned int conversion bug in the
>    printf handling code

Is this the same issue I demonstrated?  Do you already have a patch
ready?

> 3. So we're going to fix our implementation of printf

--Gisle

Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About