nasm: Buffer overflow vulnerability
Posted May 5, 2005 14:55 UTC (Thu) by
proski (subscriber, #104)
In reply to:
nasm: Buffer overflow vulnerability by nix
Parent article:
nasm: Buffer overflow vulnerability
From http://tigger.uic.edu/~jlongs2/holes/nasm.txt:
Of course, if you _run_ a program, you're authorizing the programmer to
take control of your account; but the NASM documentation does not say
that merely _assembling_ a program can have this effect. It's easy to
imagine situations in which a program is run inside a jail but assembled
outside the jail; this NASM bug means that the jail is ineffective.
(
Log in to post comments)