Skip to content

Safety rails not safe enough #1

@ajberkley

Description

@ajberkley

There are several places where I declare that the (* 8 length) and the like of restored objects is a fixnum after length has been restored as a fixnum. That's wrong. So malicious input may bypass the check by using large enough values.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions