Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 30 Mar 2012 12:27:31 -0600
From: Jeff Law <law@...hat.com>
To: Solar Designer <solar@...nwall.com>
CC: oss-security@...ts.openwall.com
Subject: Re: glibc crypt(3), crypt_r(3), PHP crypt() may use
 alloca()

On 03/30/2012 12:17 PM, Solar Designer wrote:
>
> Wow.  I thought we'd need to notify glibc developers more specifically
> for this to happen, which I did not do yet for lack of decision on what
> to do with the return value.
I think the right way to handle the return value is to return NULL for 
these cases.  It's posix complaint and the glibc crypt routines already 
return NULL for exceptional conditions.

Jeff

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.