Comment 6 for bug 779391

Revision history for this message
Kees Cook (kees) wrote :

AAaargh. Who reimplements sprintf!? I am working on hardy and dapper now. Will have this uploaded shortly. Thanks for double-checking and getting the Lucid and Oneiric patches ready!

At least full ASLR (PIE[1]) is in place in Lucid and later, so exploiting this is difficult, but not impossible.

[1] https://wiki.ubuntu.com/Security/Features#pie