---

Lynx 2.8 overflow

Mixter posted to
BUGTRAQ:

Sorry if this is a well-known bug

This was tested with Lynx Version 2.8.1pre.9. An IMG tag with a
width of about 250 chars instantly crashes this version (and
probably others). This bug is not limited to lynx, it was first
discovered with MSIE 4/5.

As far as I know, the overflow is due to a limited and
non-checked buffer in function strrchr() …

Here is some sample code:
<img
width=000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001>

FAILED<br><br>

Mixter

———————-
members.xoom.com/i0wnu

Get the Free Newsletter!

Subscribe to Developer Insider for top news, trends, & analysis