Subject: Re: vixie-crontab vunerable?
To: Jason Thorpe <thorpej@nas.nasa.gov>
From: matthew green <mrg@eterna.com.au>
List: current-users
Date: 12/17/1996 10:56:06
   We already have a __warn_references() for gets(), so adding it to the
   others would probably be appropriate.

there are 3 problem functions in particular (at least, 3 that i've
been looking at).  sprintf(), strcat() and strcpy().  the problem
with adding a __warn_references() call to them is that it's possible
(and easy!) to use them 'safely'.



.mrg.