[Esd-l] W32.Erkez.D@mm may bypass sanitizer

John D. Hardin jhardin at impsec.org
Tue Dec 14 21:10:14 PST 2004


All:

http://securityresponse.symantec.com/avcenter/venc/data/w32.erkez.d@mm.html

I've had a couple of these get further than they should have,
highlighting a bug. It's possible that some variants of this will
bypass the sanitizer, and it's possible that the problem is limited
to the 1.148pre2 release.

The 1.148pre3 dev release closes the hole.

--
 John Hardin KA7OHZ    ICQ#15735746    http://www.impsec.org/~jhardin/
 jhardin at impsec.org    FALaholic #11174    pgpk -a jhardin at impsec.org
 key: 0xB8732E79 - 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
What nuts do with guns is terrible, certainly. But what evil or crazy
people do with *anything* is not a valid argument for banning that item.
                                  -- John C. Randolph <jcr at idiom.com>
-----------------------------------------------------------------------


More information about the esd-l mailing list