|
From: | Anthony Liguori |
Subject: | Re: [Qemu-devel] [PING 0.14] Missing patches (mostly fixes) |
Date: | Fri, 04 Feb 2011 11:59:02 -0600 |
User-agent: | Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1.15) Gecko/20101027 Lightning/1.0b1 Thunderbird/3.0.10 |
On 02/04/2011 11:36 AM, Stefan Weil wrote:
Hi Anthony, please accept that even if you said something multiple times, other people might have a different point of view.
Yup, just making my point of view clear.
QEMU is team work, isn't it? Both positives are correct, there was no false positive: Reading strings from external files into limited memory without limiting their length is bad. Even if it works with some input data, this kind of programming will be copied by novice programmers and used with data which is critical.
This is why I dislike patches like this, because the discussion about whether it really is important or not ends up being a huge distraction.
Regards, Anthony Liguori
[Prev in Thread] | Current Thread | [Next in Thread] |