|
|
Article: VC++.NET Compiler Called "Vulnerability Seeder".(Cigital warns of flaw in Microsoft's Visual C++.NET compiler)
- Article from:
- The Online Reporter
- Article date:
- February 25, 2002
CopyrightCOPYRIGHT 2002 Rider Research, Inc. This material is published under license from the publisher through the Gale Group, Farmington Hills, Michigan. All inquiries regarding rights should be directed to the Gale Group. (Hide copyright information)
|
A software risk management consultancy by the name of Cigital claims the protection mechanism in Microsoft's Visual C++.NET compiler is vulnerable to attack.
The mechanism is called /GS and is there to handle buffer overflows, the cause of a lot of Microsoft's security woes.
Cigital warns against using it. It claims /GS resembles a piece of third-party widgetry called StackGuard and it takes a dim view of StackGuard. "The StackGuard mechanism makes a poor efficiency/security tradeoff, especially as implemented in Microsoft's compiler," it says.
Microsoft claims /GS has nothing to do with StackGuard.
Cigital took impetus from a white ...