Re: A static analyzer found 3 potential security bugs in our code

2013-10-31 Thread André Reinald
Le 13-10-31 01:12, Jesse Ruderman a écrit : The three bug reports: https://bugzilla.mozilla.org/show_bug.cgi?id=823336 https://bugzilla.mozilla.org/show_bug.cgi?id=823338 https://bugzilla.mozilla.org/show_bug.cgi?id=826201 Short and efficient answer. Thanks Jesse! Do we still run this (and ma

Re: A static analyzer found 3 potential security bugs in our code

2013-10-31 Thread André Reinald
Le 13-10-30 17:55, Florian Bender a écrit : Shouldn't this be posted to m.d.security? As far as I understood, m.d.security was more targeted at implementing security standards, not security bugs corrections. But I may be wrong. ___ dev-platform mail

Re: A static analyzer found 3 potential security bugs in our code

2013-10-30 Thread Jesse Ruderman
The three bug reports: https://bugzilla.mozilla.org/show_bug.cgi?id=823336 https://bugzilla.mozilla.org/show_bug.cgi?id=823338 https://bugzilla.mozilla.org/show_bug.cgi?id=826201 ___ dev-platform mailing list dev-platform@lists.mozilla.org https://lists

Re: A static analyzer found 3 potential security bugs in our code

2013-10-30 Thread Mike Hommey
On Wed, Oct 30, 2013 at 09:56:46AM -0700, Chris Peterson wrote: > On 10/30/13, 9:06 AM, André Reinald wrote: > >http://www.itworld.com/security/380406/how-your-compiler-may-be-compromising-application-security > > > >STACK was run against a number of systems written in C/C++ and it found > >160 ne

Re: A static analyzer found 3 potential security bugs in our code

2013-10-30 Thread Florian Bender
Shouldn't this be posted to m.d.security? ___ dev-platform mailing list dev-platform@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-platform

Re: A static analyzer found 3 potential security bugs in our code

2013-10-30 Thread Chris Peterson
On 10/30/13, 9:06 AM, André Reinald wrote: http://www.itworld.com/security/380406/how-your-compiler-may-be-compromising-application-security STACK was run against a number of systems written in C/C++ and it found 160 new bugs in the systems tested, including... Mozilla (3)... If they only fou

A static analyzer found 3 potential security bugs in our code

2013-10-30 Thread André Reinald
http://www.itworld.com/security/380406/how-your-compiler-may-be-compromising-application-security Quote: STACK was run against a number of systems written in C/C++ and it found 160 new bugs in the systems tested, including... Mozilla (3)... I thought we could make use of it.