This is the mail archive of the
libc-alpha@sourceware.org
mailing list for the glibc project.
Re: alloca vs malloc
- From: "Joseph S. Myers" <joseph at codesourcery dot com>
- To: Jeff Law <law at redhat dot com>
- Cc: OndÅej BÃlka <neleai at seznam dot cz>, Florian Weimer <fweimer at redhat dot com>, Will Newton <will dot newton at linaro dot org>, Konstantin Serebryany <konstantin dot s dot serebryany at gmail dot com>, GNU C Library <libc-alpha at sourceware dot org>
- Date: Fri, 16 May 2014 23:55:04 +0000
- Subject: Re: alloca vs malloc
- Authentication-results: sourceware.org; auth=none
- References: <CAGQ9bdw135gBO+cTQx3Ws1GrRgFsi8-j=Y_mZ=ixebpPzB4gXw at mail dot gmail dot com> <53760025 dot 10204 at redhat dot com> <CANu=DmhF=PZBVHtOPw5ZMCHjcy6vqdCvrRvY+xO9hzfkjTCRQA at mail dot gmail dot com> <53760826 dot 6090203 at redhat dot com> <20140516135304 dot GA29829 at domone dot podge> <537630BB dot 7030701 at redhat dot com> <Pine dot LNX dot 4 dot 64 dot 1405161626230 dot 18605 at digraph dot polyomino dot org dot uk> <53768A69 dot 3010509 at redhat dot com>
On Fri, 16 May 2014, Jeff Law wrote:
> > E.g. bug 16618 (something I'd have
> > thought would be a natural case for a CVE - wscanf may not be widely used,
> > but it's still a buffer overrun if wscanf is used -
> More likely nobody's contacted the appropriate folks. Sounds like it'd be
> worth of a CVE to me.
I'm sort of presuming that some distribution security people are watching
for newly filed glibc bugs that seem CVE-worthy, and requesting CVEs.
--
Joseph S. Myers
joseph@codesourcery.com