[Owasp-esapi-c++] Test Suite and Valgrind

Kevin W. Wall kevin.w.wall at gmail.com
Fri Apr 9 15:14:11 EDT 2004


Jeff Walton wrote:

> Kevin Wall wrote:
>> If you really want to know how to handle the valgrind issues, I'd suggest a
>> post to the Boost and valgrind forums.
> http://lists.boost.org/boost-users/2011/08/70235.php

Perhaps a better question is, if valgrind has this many complaints about the
Boost libraries (or is this only about Boost::Test?), can we really
trust it to NOT
have memory leaks? Because, if it does, maybe we should rethink about using it,
or perhaps divert some effort into fixing the Boost libraries. If
Boost has memory
leaks that can be exploited, it can be used to attack apps that are
using ESAPI for C++
and there's very little we can do about that.

Thoughts???
-kevin
-- 
Blog: http://off-the-wall-security.blogspot.com/
"The most likely way for the world to be destroyed, most experts agree,
is by accident. That's where we come in; we're computer professionals.
We *cause* accidents."        -- Nathaniel Borenstein


More information about the Owasp-esapi-c++ mailing list