develooper Front page | perl.perl5.porters | Postings from December 2005

Re: Perl PR: "Security holes in Sys::Syslog"

Thread Previous | Thread Next
From:
dreamwvr
Date:
December 3, 2005 08:18
Subject:
Re: Perl PR: "Security holes in Sys::Syslog"
Message ID:
4391C23C.7080700@dreamwvr.com
Regarding the formatting fall thru holes that has been submitted. Why not
transparently convert all calls to printf() to snprintf() calls? Then it 
controls  strlen issues that might be missed. It seems every few years 
the printf sec issues arise
again in PERL. just a thought..

Best Regards,
dreamwvr@dreamwvr.com


Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About