Derek Callaway writes:
 > Curious, what's so insecure about syslog()?

A version was subject to a buffer overflow attack.

 > > is a security disaster. It also sucks in the string library, which
 > > includes the well-known security hole sprintf().
 > 
 > Does that sprintf() introduce an overflow or is it something else?

sprintf(), if used with unchecked data, practically *mandates* an
overflow.

-- 
-russ nelson <[EMAIL PROTECTED]>  http://russnelson.com
Crynwr sells support for free software  | PGPok | "Ask not what your country
521 Pleasant Valley Rd. | +1 315 268 1925 voice | can force other people to
Potsdam, NY 13676-3213  | +1 315 268 9201 FAX   | do for you..."  -Perry M.

Reply via email to