Eric W. Biederman wrote:

> 
> Hmm.  gzip does call malloc so without the docmil update a buffer
> overrun could be a problem.  With a different compression level
> the pattern of mallocs use by inflate.c would be different.
> 
> It would be nice to see if code that does not decompress from
> LinuxBIOS could be placed in a file and tested with gunzip.  We may
> actually be experience intermittent data failure.  
> 
> The most interesting thing is the buffer overflow in
> memcpy_from_docmil has existed since the code was added to CVS.  So
> historically small bugs in the stream driver might not show
> immediately.
> 


So I am fscked up again ?? That's really embarassing.

Ollie


Reply via email to