[Owasp-esapi-c++] Test Suite and Valgrind
Kevin W. Wall
kevin.w.wall at gmail.com
Fri Apr 9 15:14:11 EDT 2004
Jeff Walton wrote:
> Kevin Wall wrote:
>> If you really want to know how to handle the valgrind issues, I'd suggest a
>> post to the Boost and valgrind forums.
> http://lists.boost.org/boost-users/2011/08/70235.php
Perhaps a better question is, if valgrind has this many complaints about the
Boost libraries (or is this only about Boost::Test?), can we really
trust it to NOT
have memory leaks? Because, if it does, maybe we should rethink about using it,
or perhaps divert some effort into fixing the Boost libraries. If
Boost has memory
leaks that can be exploited, it can be used to attack apps that are
using ESAPI for C++
and there's very little we can do about that.
Thoughts???
-kevin
--
Blog: http://off-the-wall-security.blogspot.com/
"The most likely way for the world to be destroyed, most experts agree,
is by accident. That's where we come in; we're computer professionals.
We *cause* accidents." -- Nathaniel Borenstein
More information about the Owasp-esapi-c++
mailing list