US-CERT Vulnerability Note VU#162289

Tom Truscott Tom.Truscott@sas.com
Mon Apr 7 20:33:00 GMT 2008


Here is an unintended bug I encountered recently, hopefully the "cert" warning will catch this one too.

   int okay_to_increment (int i)
   {
      if (i + 1 < i)
        return 0;  /* adding 1 would cause overflow */
      return 1;    /* adding 1 is safe */
   }

Any sort of bug can cause a security vulnerability, so I recommend that gcc developers work harder on warning messages.

Tom Truscott



More information about the Gcc mailing list