GCC 3.0.3 PRs

Benjamin Kosnik bkoz@redhat.com
Fri Dec 7 16:08:00 GMT 2001


> I think that 3720 should be considered a must-fix.  If people use stream
> I/O in security-critical programs, this kind of buffer overflow could lead
> to root exploits in programs that would be perfectly safe with a
> correct iostreams implementation.  I don't think it's ethical for us to
> ship with such a bug.

this is fixed in mainline by breaking the ABI.

> Also, it shouldn't be hard to fix it once agreement is reached on how.
> All that's needed is an upper bound on buffer size.

about 4962 bytes, apparently

Mark, I'm too busy to do this before Dec 15 sorry



More information about the Gcc mailing list