Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Buffer overflow and format string overflow vulnerabilities

View through CrossRef
Abstract Buffer overflow vulnerabilities are among the most widespread of security problems. Numerous incidents of buffer overflow attacks have been reported and many solutions have been proposed, but a solution that is both complete and highly practical is yet to be found. Another kind of vulnerability called format string overflow has recently been found and although not as widespread as buffer overflow, format string overflow attacks are no less dangerous. This article surveys representative techniques of exploiting buffer overflow and format string overflow vulnerabilities and their currently available defensive measures. We also describe our buffer overflow detection technique that range checks the referenced buffers at run‐time. We augment executable files with the type information of automatic buffers (local variables and parameters of functions) and static buffers (global variables in the data / bss section) and maintain the sizes of allocated heap buffers in order to detect an actual occurrence of buffer overflow. We describe a simple implementation with which we currently protect vulnerable copy functions in the C library. Copyright © 2003 John Wiley & Sons, Ltd.
Title: Buffer overflow and format string overflow vulnerabilities
Description:
Abstract Buffer overflow vulnerabilities are among the most widespread of security problems.
Numerous incidents of buffer overflow attacks have been reported and many solutions have been proposed, but a solution that is both complete and highly practical is yet to be found.
Another kind of vulnerability called format string overflow has recently been found and although not as widespread as buffer overflow, format string overflow attacks are no less dangerous.
This article surveys representative techniques of exploiting buffer overflow and format string overflow vulnerabilities and their currently available defensive measures.
We also describe our buffer overflow detection technique that range checks the referenced buffers at run‐time.
We augment executable files with the type information of automatic buffers (local variables and parameters of functions) and static buffers (global variables in the data / bss section) and maintain the sizes of allocated heap buffers in order to detect an actual occurrence of buffer overflow.
We describe a simple implementation with which we currently protect vulnerable copy functions in the C library.
Copyright © 2003 John Wiley & Sons, Ltd.

Related Results

Environmental Surveillance Protocols for Highly Pathogenic Avian Influenza (HPAI) v2
Environmental Surveillance Protocols for Highly Pathogenic Avian Influenza (HPAI) v2
EnvironmentalSurveillance Protocols for Highly Pathogenic Avian Influenza (HPAI) This comprehensive protocol suite enables systematic environmental surveillance for avian influenza...
Embracing the screen of mediated environments
Embracing the screen of mediated environments
<p>This dissertation examines the “buffer effect,” an important but understudied feature of computer-mediated communication (CMC). Research on the buffer effect posits that C...
Parameterized Strings: Algorithms and Applications
Parameterized Strings: Algorithms and Applications
The parameterized string (p-string), a generalization of the traditional string, is composed of constant and parameter symbols. A parameterized match (p-match) exists between two p...
Optimum pH Buffer of Phosphate and Carbonate on The Crude Extraction of Uricase Enzyme from Goat Liver
Optimum pH Buffer of Phosphate and Carbonate on The Crude Extraction of Uricase Enzyme from Goat Liver
Uricase enzyme (urate oxidase) is an enzyme that catalyze the oxidation of uric acid in the presence of oxygen to produce allantoin, carbon dioxide (CO2) and hydrogen peroxide (H2O...
Lectin C gene analysis v1
Lectin C gene analysis v1
Mammalian Tissue Total RNA Purification Protocol by GeneJET RNA Purification Kit (Thermo Scientific, USA) Before starting: • Supplement the required amount of Lysis Buffer with β-...
A taxonomy of endpoint vulnerabilities and affected blockchain architecture layers
A taxonomy of endpoint vulnerabilities and affected blockchain architecture layers
AbstractBlockchain technology has gained significant attention and adoption due to its decentralized nature, and promising secure and immutable transactions. The interpretation of ...
Understanding and exploiting overflow metabolism in biotechnology
Understanding and exploiting overflow metabolism in biotechnology
Comprendre et exploiter le métabolisme d'overflow en biotechnologie Le métabolisme overflow est un phénomène hautement conservé qui désigne la production de métabol...
Accurate Prediction of Buffer Air Temperatures Using Lumped Heat Transfer Method
Accurate Prediction of Buffer Air Temperatures Using Lumped Heat Transfer Method
Abstract Buffer air system plays a vital role in gas turbine engines as it pressurizes bearing compartments, thermal conditioning of life limiting parts, purging the...

Back to Top