Comment 1 for bug 388606

Revision history for this message
Kees Cook (kees) wrote :

relpOffersToString does not bounds-check the output string (even has a "TODO" listed), as it uses a fixed 4096 size. Once this is fixed, I can approve the MIR.