Ethereal-dev: [Ethereal-dev] Re: possible crashes in packet-asn1.c and packet-ieee80211.c: snp

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: ronnie sahlberg <ronniesahlberg@xxxxxxxxx>
Date: Thu, 18 Aug 2005 04:47:23 -0400
i added the list of sprintf  callers to the ememification wiki    so
that people want to chip in can have a stab at files and start picking
the easy/obvious ones.



On 8/18/05, Ulf Lamping <ulf.lamping@xxxxxx> wrote:
> ronnie sahlberg wrote:
> 
> >Nice work.
> >  
> >
> :-)
> 
> >I think requiring 1.2.3 is fine,   those
> >such as myself with older versions are very few and can live with
> suboptimal
> >stability/broken g_snprintf()
> >
> >
> >If you run   
> >grep sprintf | sed -e "s/:.*$//" | sort | uniq
> >in epan and epan/dissectors
> >you get a lot of hits.
> >  
> >
> Yes, that's the next step.
> 
> >Can you update the wiki and add a section that all these files need to
> >be audited and fixed up?
> >  
> >
> I've added:
> 
> http://wiki.ethereal.com/Development/InsecureCalls
> 
> I've also placed a note, that we might use static code analysis tools 
> like flawfinder to find other similar problems.
> 
> Regards, ULFL
> 
> _______________________________________________
> Ethereal-dev mailing list
> Ethereal-dev@xxxxxxxxxxxx
> http://www.ethereal.com/mailman/listinfo/ethereal-dev
>