Security flaws in FAPG 0.41 and related patches
authorSebastian Pipping <sebastian@pipping.org>
Sat, 21 Jun 2008 00:14:19 +0000 (02:14 +0200)
committerAntoine Jacquet <royale@zerezo.com>
Wed, 30 Jul 2008 22:57:35 +0000 (00:57 +0200)
Hello Antoine!

As part of a security course at university our group has
studied code of FAPG 0.38. With the help of Splint [1]
we were able to find two security flaws that are still
present in FAPG 0.41.

I have attached a patch to this mail for each flaw.
Would be cool if you could include these patches
in the next FAPG release.

Best regards,

Sebastian

[1] http://www.splint.org/

Signed-off-by: Antoine Jacquet <royale@zerezo.com>

No differences found