Path: utzoo!utgpu!news-server.csri.toronto.edu!bonnie.concordia.ca!uunet!tut.cis.ohio-state.edu!pacific.mps.ohio-state.edu!linac!att!cbnews!junk1 From: junk1@cbnews.att.com (eric.a.olson) Newsgroups: comp.unix.sysv386 Subject: Re: SECURITY BUG IN INTERACTIVE UNIX SYSV386 Message-ID: <1991Feb20.124535.10669@cbnews.att.com> Date: 20 Feb 91 12:45:35 GMT References: <15297@uudell.dell.com> <113@calcite.UUCP> Organization: AT&T Bell Laboratories Lines: 10 In article <113@calcite.UUCP> vjs@calcite.UUCP (Vernon Schryver) writes: >There is no plausible test that would have found the big, bad bug. Please >don't suggest a program that would write to all possible invalid pages in >the hope of causing something unexpected without providing a way to do that >quickly enough to be useful, ... Oh, give me a break. SOMEONE must have been responsible for seeing whether or not writes to illegal pages get stopped by a segmentation fault. It doesn't take _that_ long to go thru your address space.