[tor-bugs] #18162 [Tor]: Potential heap corruption in smartlist_add(), smartlist_insert()
Tor Bug Tracker & Wiki
blackhole at torproject.org
Fri Jan 29 15:16:58 UTC 2016
#18162: Potential heap corruption in smartlist_add(), smartlist_insert()
-------------------------------------------------+-------------------------
Reporter: asn | Owner: nickm
Type: defect | Status:
Priority: High | needs_review
Component: Tor | Milestone: Tor:
Severity: Normal | 0.2.8.x-final
Keywords: security 025-backport 026-backport | Version:
027-backport 024-backport | Resolution:
Parent ID: | Actual Points:
Sponsor: | Points:
-------------------------------------------------+-------------------------
Comment (by bugzilla):
Haven't digged it deeply, but why signed {{{int}}} for size? Why
{{{int}}}? Isn't {{{size_t}}} enough? {{{uint64_t}}} then?
All code with signed {{{size}}} must be rewritten even if it is very
difficult (cause it's "bug by design").
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18162#comment:12>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list