Shoutbox

ALERT!!! BUFFER OVERFLOW FOUND IN MSG PLUS 2 - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Messenger Plus! for Live Messenger (/forumdisplay.php?fid=4)
+---- Forum: WLM Plus! General (/forumdisplay.php?fid=23)
+----- Thread: ALERT!!! BUFFER OVERFLOW FOUND IN MSG PLUS 2 (/showthread.php?tid=24633)

ALERT!!! BUFFER OVERFLOW FOUND IN MSG PLUS 2 by XM4ST3RX on 05-02-2004 at 03:00 AM

I dunno if i am the first to spot this but im guessing i am seing as it has not been fixed.

When setting your status away and the Personalised Status window is displayed... i intentionally entered alot of characters just to see if it would, even though i had 99% negative thought of it happening...

But silly Patchou hasnt seemed to enter a max length for the text field :p



Anyways, thought i'd mention it seeing as though it's another error out of the way :)... i have not checked other fields so make sure you check them all Patchou :p


RE: ALERT!!! BUFFER OVERFLOW FOUND IN MSG PLUS 2 by Dane on 05-02-2004 at 03:09 AM

I dont think this is a big bug.  It is fixed in MsgPlus3 as far as I can tell.


RE: ALERT!!! BUFFER OVERFLOW FOUND IN MSG PLUS 2 by DXtremz on 05-02-2004 at 03:11 AM

It has the potential to be, tho it won't hurt anything much, by that I mean, it doesn't allow anything to be exploited. I'll email Patchou with the problem to make sure he gets it faster.


RE: ALERT!!! BUFFER OVERFLOW FOUND IN MSG PLUS 2 by XM4ST3RX on 05-02-2004 at 03:15 AM

Yes, i have been checking a few such as text fields to specify directories... directories cannot be unlimited chars in size... so theres more than one...



*wants to be a beta tester :D*


RE: ALERT!!! BUFFER OVERFLOW FOUND IN MSG PLUS 2 by Patchou on 05-02-2004 at 03:16 AM

Silly Patchou already noticed it and he fixed it in Plus!3 :). A max length was already set but one of the buffers used to manipulate the text was not controlled.

Also... silly Patchou would liek to add that there's nothing to "alert" about, "buffer overflow" are generally bad only when network communications are involved.

SillyPatch


RE: ALERT!!! BUFFER OVERFLOW FOUND IN MSG PLUS 2 by Patchou on 05-02-2004 at 03:18 AM

As for the other edit boxes that are not explicitly limited, don't worry, I always limit general input to 1024 characters in my code, there's no risk of overflow there.


RE: ALERT!!! BUFFER OVERFLOW FOUND IN MSG PLUS 2 by XM4ST3RX on 05-02-2004 at 11:45 PM

Just thought i'd post the error because im bored and thought i'd come visit :D

[Image: attachment.php?pid=237098]