Re: A static analyzer found 3 potential security bugs in our code

2013-10-31 Thread André Reinald
Le 13-10-30 17:55, Florian Bender a écrit : Shouldn't this be posted to m.d.security? As far as I understood, m.d.security was more targeted at implementing security standards, not security bugs corrections. But I may be wrong. ___ dev-platform

Re: A static analyzer found 3 potential security bugs in our code

2013-10-31 Thread André Reinald
Le 13-10-31 01:12, Jesse Ruderman a écrit : The three bug reports: https://bugzilla.mozilla.org/show_bug.cgi?id=823336 https://bugzilla.mozilla.org/show_bug.cgi?id=823338 https://bugzilla.mozilla.org/show_bug.cgi?id=826201 Short and efficient answer. Thanks Jesse! Do we still run this (and

A static analyzer found 3 potential security bugs in our code

2013-10-30 Thread André Reinald
http://www.itworld.com/security/380406/how-your-compiler-may-be-compromising-application-security Quote: STACK was run against a number of systems written in C/C++ and it found 160 new bugs in the systems tested, including... Mozilla (3)... I thought we could make use of it.

Re: A static analyzer found 3 potential security bugs in our code

2013-10-30 Thread Chris Peterson
On 10/30/13, 9:06 AM, André Reinald wrote: http://www.itworld.com/security/380406/how-your-compiler-may-be-compromising-application-security STACK was run against a number of systems written in C/C++ and it found 160 new bugs in the systems tested, including... Mozilla (3)... If they only

Re: A static analyzer found 3 potential security bugs in our code

2013-10-30 Thread Florian Bender
Shouldn't this be posted to m.d.security? ___ dev-platform mailing list dev-platform@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-platform

Re: A static analyzer found 3 potential security bugs in our code

2013-10-30 Thread Jesse Ruderman
The three bug reports: https://bugzilla.mozilla.org/show_bug.cgi?id=823336 https://bugzilla.mozilla.org/show_bug.cgi?id=823338 https://bugzilla.mozilla.org/show_bug.cgi?id=826201 ___ dev-platform mailing list dev-platform@lists.mozilla.org