logoalt Hacker News

rubendevyesterday at 6:03 PM1 replyview on HN

With a capable static analyzer that is not true. In many common cases they can deduce the possible ranges of values based on branching checks along the data flow path, and if that range falls within the buffer then it does not report it.


Replies

tptacekyesterday at 7:09 PM

Be specific. Which analyzer are you talking about and which specific targets are you saying they were successful at?

show 1 reply