Subject: Re: exploit with memcpy()
To: None <xs@kittenz.org>
From: Bill Squier <groo@old-ones.com>
List: tech-userlevel
Date: 07/03/2002 15:12:07
On Tue, Jul 02, 2002 at 08:13:43PM +0100, xs@kittenz.org wrote:
> on Tue, Jul 02, 2002 at 03:24:47PM +0000, Christos Zoulas wrote:
> > And we should strive to eliminate functions in libc that write errors
> > and warnings to stderr...
> 
> The only thing that springs to mind that does this is malloc(3). I'm sure

And everything that uses {err,warn}[x].  Christos and I have had some
discussions about what to do, but they generally end in a decision to have
another Ketel One or beer.

-- 
Bill Squier (groo@old-ones.com)                          http://www.netbsd.org

        I know I don't deserve another chance, but this _is_ America,
        and as an American, aren't I entitled to one?  --Sideshow Bob.