Coverity releases first defect survey results
Posted Mar 6, 2006 19:11 UTC (Mon) by
jwb (guest, #15467)
Parent article:
Coverity releases first defect survey results
Ethereal's vulnerabilities are almost always in plug-in code modules. Some random person will contribute a dissector for, say, the protocol used by AIM. The bugs nearly all take the form of unprotected string copies into arrays of type char, either using a length that should be considered untrusted, or by null-termination.
Maybe the Coverity checker didn't look at the plug-ins.
(
Log in to post comments)