ie8 fix
madison

Discussion on:

Message 2 of 1
0 Votes
+ -
Code snippet
D T Schmitz 26th Nov 2007
It would have been interesting to have a read your code snippet with your comments on how the exploit (buffer overrun) succeeded.

For example, on a parameter pass and within a function call, was strcpy() being called vs strncpy() with len n check that produced the side effect? Or was it void * parameter that was cast incorrectly?

Thanks Jeremy! happy
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

ie8 fix