LWN.net Logo

nasm: Buffer overflow vulnerability

nasm: Buffer overflow vulnerability

Posted May 5, 2005 14:55 UTC (Thu) by proski (subscriber, #104)
In reply to: nasm: Buffer overflow vulnerability by nix
Parent article: nasm: Buffer overflow vulnerability

From http://tigger.uic.edu/~jlongs2/holes/nasm.txt:

Of course, if you _run_ a program, you're authorizing the programmer to take control of your account; but the NASM documentation does not say that merely _assembling_ a program can have this effect. It's easy to imagine situations in which a program is run inside a jail but assembled outside the jail; this NASM bug means that the jail is ineffective.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds