Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>If you had the same version of OpenSMTPD running on a generic Linux kernel or on Mac OS X, it was vulnerable

You're completely wrong, stack canaries have nothing to do with kernels, they're a compiler option, gcc has them enabled by default, clang has them enabled by default. So no, running OpenSMTPD on Linux or OS X would not make that vulnerability exploitable.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: