LWN.net Logo

Open Source Security Report

Open Source Security Report

Posted Jun 3, 2008 22:06 UTC (Tue) by lunz (subscriber, #43534)
In reply to: Open Source Security Report by orospakr
Parent article: Open Source Security Report

You guys are aware that the openssl bug was introduced by someone trying to silence warnings
from a source code checker not unlike Coverity's, right?


(Log in to post comments)

Open Source Security Report

Posted Jun 3, 2008 22:34 UTC (Tue) by nix (subscriber, #2304) [Link]

Valgrind isn't a source code checker, and its mechanism of action (JITted 
dynamic binary instrumentation) is utterly different from Coverity's. Also 
they don't spot especially similar classes of problem.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds