Firewall Wizards mailing list archives

Re: Buffer Overruns


From: Matt Curtin <cmcurtin () interhack net>
Date: 17 Dec 1999 22:20:02 -0500

On Fri, 17 Dec 1999 06:16:32 -0500,
Michael Kelly <michaelkelley () home com> said:

Michael>  I really feel silly asking this, but; Can these buffer
Michael> overrun bugs penetrate firewalls? I'm trying to convince the
Michael> boss to ditch IE in favor of Netscape. (which is only
Michael> slightly better)

A buffer overrun problem is possible anytime that something can give
more input than the listener is expecting and will properly handle.

That means it will traverse all protocols, network architecture
components, applications, platforms, etc., that are in the middle.  If 
the source of the data can give more than the receiver can reasonably
handle, it's vulnerable.  A firewall will offer no protection.

-- 
Matt Curtin cmcurtin () interhack net http://www.interhack.net/people/cmcurtin/



Current thread: