Bufier Over∞ow and Format String Over∞ow Vulnerabilities
Kyung-suk Lhee, Steve J. Chapin · 2002
SUMMARY Bufier over∞ow vulnerabilities are among the most widespread of security problems. Numerous incidents of bufier over∞ow attacks have been reported and many solutions have been proposed, but a solution that is both complete and highly practical is yet to be found. Another kind of vulnerability called format string over∞ow has recently been found, and though not as popular as bufier over∞ow, format string over∞ow attacks are no less dangerous. This article surveys representative techniques of exploiting bufier over∞ow and format string over∞ow vulnerabilities and their currently available defensive measures. We also describe our bufier over∞ow detection technique that range checks the referenced bufiers at run time. We augment executable flles with type information of automatic bufiers (local variables and parameters of functions) and static bufiers (global variables in the data/bss section), and maintain the sizes of allocated heap bufiers in order to detect an actual occurrence of bufier over∞ow. We describe a simple implementation with which we currently protect vulnerable copy functions in the C library.