comp.lang.ada
 help / color / mirror / Atom feed
From: Georg Bauhaus <rm.dash-bauhaus@futureapps.de>
Subject: Re: Web browser in Ada
Date: Fri, 23 Apr 2010 16:37:03 +0200
Date: 2010-04-23T16:37:04+02:00	[thread overview]
Message-ID: <4bd1b090$0$7651$9b4e6d93@newsspool1.arcor-online.net> (raw)
In-Reply-To: <0bf9425c-32a1-4b93-b938-ae4a4e24a761@c21g2000yqk.googlegroups.com>

On 23.04.10 15:56, Maciej Sobczak wrote:

> 
> Could you refer to an existing browser vulnerability that is related
> to the core browser engine and that would be avoided by choosing
> another language?
> (I'm genuinely interested)


Does CSS count? Or image rendering components?
"buffer overflow" + {ie6, mozilla, ...} produce a number of
search results.  Then there is the presence of DEP in recent
MS systems brough to your desktop with IE7 ...

Buffer overflow continues to rank high, e.g. in the 2010 SANS Top 25:
http://cwe.mitre.org/data/definitions/120.html

Integer overflow or wraparound and improper array indexing rank
somewhat lower, but are present, too.

BTW, why do we still subscribe to the notion "integer overflow"
when the one thing that any sequence of what is commonly known
as integers cannot possibly do is to overflow?  Maybe the
wording is at the heart of the problem.

I think it is adequate and pedagogical to call it "int overflow".





  reply	other threads:[~2010-04-23 14:37 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-04-23  8:03 Web browser in Ada Gautier write-only
2010-04-23 13:56 ` Maciej Sobczak
2010-04-23 14:37   ` Georg Bauhaus [this message]
2010-04-27 11:41     ` Martin Krischik
2010-04-27 12:22       ` Georg Bauhaus
2010-04-27 14:00         ` AdaMagica
2010-04-27 15:30           ` Integer overflow is int overflow (Re: Web browser in Ada) Georg Bauhaus
2010-04-27 16:13             ` Dmitry A. Kazakov
2010-04-27 17:09               ` Georg Bauhaus
2010-04-27 17:56                 ` Dmitry A. Kazakov
2010-04-23 21:33   ` Web browser in Ada Gautier write-only
2010-04-24  0:38     ` Peter C. Chapin
2010-04-25  5:38       ` Gautier write-only
2010-04-25 16:24         ` Peter C. Chapin
2010-04-25 10:41       ` Georg Bauhaus
2010-04-25 16:29         ` Peter C. Chapin
2010-04-26 15:37       ` Warren
2010-04-24  9:51 ` leonid
2010-04-25  5:04   ` Gautier write-only
replies disabled

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox