[VIM] SUNALERT:102554 "drain_squeue" is probably really squeue_drain

security curmudgeon jericho at attrition.org
Thu Aug 31 06:06:56 EDT 2006


: An alert CVE analyst spotted this...

Very alert..

:   ACCURACY: The text of the advisory says "drain_squeue" but the stack
:   trace says "<trap>ip:squeue_drain+0x114." It seems likely that all
:   instances of drain_squeue are wrong. Running nm on
:   /kernel/strmod/sparcv9/ip on a Solaris 10 system locates an
:   squeue_drain function but no drain_squeue function.

Given the Sun advisory specifically says 'drain_squeue'.

Outstanding observation!


More information about the VIM mailing list