Hi Nick,

There isn't anything in the server to prevent the scenario that you described, as far as I know.

-Phil

On 06/01/2010 12:57 PM, Nicholas Mills wrote:
Hey all,

Is there any code in place to prevent buffer overflows when decoding server messages (requests and responses)? In particular I'm thinking of the variable-length types like string that are prefixed with their size. It seems to me that if the size is encoded incorrectly then there is nothing to prevent the server from attempting to read past the end of the request data.

Buffer overflows are a concern for me because I'm using the encode/decode functions to serialize some security data. I'd like the implementation to be as robust as possible; however, if the server code itself doesn't protect against buffer overflows then there's not much point to me adding it only to my code.

Thanks,

Nick


_______________________________________________
Pvfs2-developers mailing list
[email protected]
http://www.beowulf-underground.org/mailman/listinfo/pvfs2-developers

_______________________________________________
Pvfs2-developers mailing list
[email protected]
http://www.beowulf-underground.org/mailman/listinfo/pvfs2-developers

Reply via email to