Re: off by 1 bug in poa.c



Hi Paco,

On Tue, 2003-03-25 at 22:09, Paco Moya wrote:
> In ORBit 2.6.0 poa.c:1340 it can be read:

	Looks right to me off hand; it seems like it's checking for a '\0'
inside the _buffer. I'd imagine reading off the end of that (length+1)
would be a bad move / memory problem.

	What issue are you seeing here ? do you have a regression test we can
easily add to test/everything to test this problem now and in future ?

	Thanks,

		Michael.

-- 
 mmeeks@gnu.org  <><, Pseudo Engineer, itinerant idiot




[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]