fetchmail-friends
[Top] [All Lists]

Re: not exploitable buffer overflow in fetchmail 5.6.0

2001-01-29 10:46:10
Rob Shinn wrote:
I'm asking because I'm working on some Web/Internet stuff and I need to
understand these issues.   Any help (Web sites, books, etc.) would be
appreciated.  Thanks.

One good place to start for secure programming recommendations is the
"secure programming" section of the OpenBSD porting page:
  http://www.openbsd.org/porting.html#security

It won't answer why one buffer overflow is exploitable and one isn't,
but that's because they should all be fixed, exploitable or not.
(What's not exploitable today may be exploitable on another system
tomorrow.)

-- 
==============================|   "A microscope locked in on one point
 Rob Funk <rfunk(_at_)funknet(_dot_)net> |Never sees what kind of room that 
it's in"
 http://www.funknet.net/rfunk |    -- Chris Mars, "Stuck in Rewind"


<Prev in Thread] Current Thread [Next in Thread>