[Bug network/15014] gethostbyname_r() returns EINVAL (22) instead of ERANGE (34) (CVE-2015-0235)

lauri.love at gmail dot com sourceware-bugzilla@sourceware.org
Wed Jan 28 12:10:00 GMT 2015


https://sourceware.org/bugzilla/show_bug.cgi?id=15014

--- Comment #5 from nsh <lauri.love at gmail dot com> ---
I appreciate that from the bug metadata it's not apparent at all, and (now)
appreciate the work that has been and continues to be put into evaluating
security implications of bugs. In this case, at least, even a trivial grep of
the diff for 'buffer' would flag a mind suitably predisposed towards suspicion.

Could there be some more low-hanging automated patch-analysis fruits? Perhaps
there exists some static analysis tool designed to classify along these lines,
or if not, some more general tool might be specialized to the task. 

I should look into it and try a little myself, I suppose, to see if I'm being
over optimistic about the like reward to invested effort. 

Best, 
nsh

-- 
You are receiving this mail because:
You are on the CC list for the bug.



More information about the Glibc-bugs mailing list