[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] [SE-2012-01] New Reflection API affected by a known 10+ years old attack
- To: Georgi Guninski <guninski@xxxxxxxxxxxx>
- Subject: Re: [Full-disclosure] [SE-2012-01] New Reflection API affected by a known 10+ years old attack
- From: Florian Weimer <fw@xxxxxxxxxxxxx>
- Date: Mon, 22 Jul 2013 23:56:26 +0200
* Georgi Guninski:
> Can Coverity find logic bugs like missing checks?
Yes, some inconsistent cheks are reported. Here's a public example
quoting some of the (textual) reporting:
<http://thread.gmane.org/gmane.comp.emulators.libvirt.cim/422/focus=423>
For real logic bugs, this will not work because hopefully, your logic
is far more concentrated and not spread all over the place. (I think
this Coverity feature works only to ensure correct error threading, as
a poor man's substitute for exceptions.)
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/