Re: Veracode reported vulnerabilities

2016-11-21 Thread Mc Security
I see that there is careful memory allocation done for DNS_RR and TLS_SCACHE_ENTRY in in dns_rr.c and tls_scache.c respectively so that buffer overflow is not caused. However, a confirmation would be great. On Mon, Nov 21, 2016 at 1:51 PM, Mc Security wrote: > Here are the line numbers for

Re: Veracode reported vulnerabilities

2016-11-21 Thread Mc Security
Here are the line numbers for the remaining two items: 1. Buffer overflow Sourcefile: dns_rr.c, Line: 129, Module: dnsblog 2. Buffer oevrflow Sourcefile: tls_scache.c, Line: 208, Module: smtpd Thanks, Mc. On Wed, Nov 16, 2016 at 9:40 PM, Mc Secuirty wrote: > Wietse: > > Thank you ver