Comment 4 for bug 317892

Revision history for this message
Kees Cook (kees) wrote :

Beyond that, I don't see anything that really stands out to me. String handling is done via C++, auto-response elements look right, sprintf-like things are done sanely, and the SQL all looks to be injection-safe. +1 from me on a quick overview audit.