This is the mail archive of the
libc-alpha@sourceware.org
mailing list for the glibc project.
Re: Policy for posting security bug reports?
On Sat, 23 Jun 2012, Rich Felker wrote:
> After attempting to exploit the bug, I've found that a duplicate of
> the exact same integer overflow elsewhere in glibc seems to make it
> impossible to exploit, so I'm just going to post it to the bug
> tracker.
FWIW, I suspect there are quite a few integer overflow bugs still present
in glibc; it would be a good class of bugs for anyone interested in
security auditing to look for (although many such bugs are likely to be
hard to exploit in practice).
--
Joseph S. Myers
joseph@codesourcery.com