Skip to content
GitLab
  • Menu
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • sac2c sac2c
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 403
    • Issues 403
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 12
    • Merge requests 12
  • Deployments
    • Deployments
    • Releases
  • Wiki
    • Wiki
  • External wiki
    • External wiki
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • sac-group
  • sac2csac2c
  • Issues
  • #1821
Closed
Open
Created Apr 07, 2010 by Clemens Grelck@cgDeveloper

format string attack on dbug.c

Bugzilla Link 694
Created on Apr 07, 2010 21:33
Resolution FIXED
Resolved on Apr 09, 2010 13:56
Version svn
OS Linux
Architecture PC

Extended Description

Some of my students from the compiler course found a flaw in the current
implementation of the dbug package (formerly known as Fred Fish). 
http://en.wikipedia.org/wiki/Format_string_attack
In essence, function arguments are directly used as printf format strings,
which is a security hole and at least bad programming practice.
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking