Unsecured API functions

Kai Blin kai.blin at gmail.com
Thu May 3 17:01:19 CDT 2007


On Thursday 03 May 2007 23:16, Tom Spear wrote:

> Otherwise I assume there would be thousands of buffer overflows that
> (malicious) people would exploit.

Noone should use gets(). There are lots of better alternatives. For the other 
deprecated functions, there are ways to check that the input is valid before 
calling it, iirc.

As far as imnplementing the secured functions in Wine, I have yet to see a 
program that's failing because it tries to use one of them.

Cheers,
Kai

-- 
Kai Blin, <kai Dot blin At gmail Dot com>
WorldForge developer   http://www.worldforge.org/
Wine developer         http://wiki.winehq.org/KaiBlin/
Samba team member      http://us1.samba.org/samba/team/
--
Will code for cotton.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://www.winehq.org/pipermail/wine-devel/attachments/20070504/d4394b27/attachment.pgp


More information about the wine-devel mailing list