This is the mail archive of the libc-alpha@sourceware.org mailing list for the glibc project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: Implement C11 annex K?


On 08/14/2014 12:02 PM, Andreas Schwab wrote:
Florian Weimer <fweimer@redhat.com> writes:

Here's a security bug which resulted from the incorrect use of strlcpy:

   <http://www.samba.org/samba/security/CVE-2014-3560>
   <https://git.samba.org/?p=samba.git;a=commitdiff;h=e6a848630d>

This only proves that strlcpy isn't any better at preventing security
bugs.

It also shows that there is a real cost to not providing strlcpy in glibc.

--
Florian Weimer / Red Hat Product Security


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]