Javascript must be enabled to continue!
Buffer overflow and format string overflow vulnerabilities
View through CrossRef
Abstract
Buffer overflow vulnerabilities are among the most widespread of security problems. Numerous incidents of buffer overflow attacks have been reported and many solutions have been proposed, but a solution that is both complete and highly practical is yet to be found. Another kind of vulnerability called format string overflow has recently been found and although not as widespread as buffer overflow, format string overflow attacks are no less dangerous.
This article surveys representative techniques of exploiting buffer overflow and format string overflow vulnerabilities and their currently available defensive measures. We also describe our buffer overflow detection technique that range checks the referenced buffers at run‐time. We augment executable files with the type information of automatic buffers (local variables and parameters of functions) and static buffers (global variables in the
data
/
bss
section) and maintain the sizes of allocated heap buffers in order to detect an actual occurrence of buffer overflow. We describe a simple implementation with which we currently protect vulnerable copy functions in the C library. Copyright © 2003 John Wiley & Sons, Ltd.
Title: Buffer overflow and format string overflow vulnerabilities
Description:
Abstract
Buffer overflow vulnerabilities are among the most widespread of security problems.
Numerous incidents of buffer overflow attacks have been reported and many solutions have been proposed, but a solution that is both complete and highly practical is yet to be found.
Another kind of vulnerability called format string overflow has recently been found and although not as widespread as buffer overflow, format string overflow attacks are no less dangerous.
This article surveys representative techniques of exploiting buffer overflow and format string overflow vulnerabilities and their currently available defensive measures.
We also describe our buffer overflow detection technique that range checks the referenced buffers at run‐time.
We augment executable files with the type information of automatic buffers (local variables and parameters of functions) and static buffers (global variables in the
data
/
bss
section) and maintain the sizes of allocated heap buffers in order to detect an actual occurrence of buffer overflow.
We describe a simple implementation with which we currently protect vulnerable copy functions in the C library.
Copyright © 2003 John Wiley & Sons, Ltd.
Related Results
Environmental Surveillance Protocols for Highly Pathogenic Avian Influenza (HPAI) v2
Environmental Surveillance Protocols for Highly Pathogenic Avian Influenza (HPAI) v2
EnvironmentalSurveillance Protocols for Highly Pathogenic Avian Influenza (HPAI) This comprehensive protocol suite enables systematic environmental surveillance for avian influenza...
Parameterized Strings: Algorithms and Applications
Parameterized Strings: Algorithms and Applications
The parameterized string (p-string), a generalization of the traditional string, is composed of constant and parameter symbols. A parameterized match (p-match) exists between two p...
Lectin C gene analysis v1
Lectin C gene analysis v1
Mammalian Tissue Total RNA Purification Protocol by GeneJET RNA Purification Kit (Thermo Scientific, USA) Before starting: • Supplement the required amount of Lysis Buffer with β-...
A taxonomy of endpoint vulnerabilities and affected blockchain architecture layers
A taxonomy of endpoint vulnerabilities and affected blockchain architecture layers
AbstractBlockchain technology has gained significant attention and adoption due to its decentralized nature, and promising secure and immutable transactions. The interpretation of ...
Numerical analysis and Experimental Investigation of Lateral vibration on Drill String under Axial Load Constrained with Horizontal Pipe
Numerical analysis and Experimental Investigation of Lateral vibration on Drill String under Axial Load Constrained with Horizontal Pipe
Abstract
Horizontal well technology is an important means to improve drilling efficiency and oil and gas production, but it is easy to generate the lateral vibration...
Axial Excitation Tool String Modelling
Axial Excitation Tool String Modelling
Current types of axial excitation tool have been shown to produce beneficial results — in terms of load transfer to the bit, general reductions in string friction and reductions in...
18-3/4 in. FullBore Wellhead System
18-3/4 in. FullBore Wellhead System
Abstract
This paper describes the development of full-bore wellheads, a new 18-3/4 in.15,000 psi W.P. system, from conception to field installation. The wellheadw...
OPTIMIZATION OF BUFFER AND PRIORITIES FOR ENSURING SECURITY IN BLUETOOTH NETWORKS
OPTIMIZATION OF BUFFER AND PRIORITIES FOR ENSURING SECURITY IN BLUETOOTH NETWORKS
B a c k g r o u n d . The optimization of buffer zone size for information protection plays a crucial role in ensuring the security of video streaming over Bluetooth wireless netwo...

