CISA, FBI call software with buffer overflow issues ‘unforgivable’

CISA, FBI call software with buffer overflow issues ‘unforgivable’ CISA, FBI call software with buffer overflow issues ‘unforgivable’

Despite “well-documented” fixes, buffer overflow vulnerabilities are quite prevalent, CISA pointed out. “For these reasons — as well as the damage exploitation of these defects can cause — CISA, FBI, and others[1] designate buffer overflow vulnerabilities as unforgivable defects.”

Manufacturers are asked to refer to the methods outlined in the alert PDF issued with the advisory to prevent and mitigate buffer overflow defects, and software users are advised to demand secure products from them that include such preventions.

Microsoft, VMWare, Ivanti flaws called out

The feds highlighted a list of buffer overflow bugs affecting leading vendors like Microsoft, Ivanti, VMWare, Citrix and RedHat, ranging from high to critical severity, and some already having in-the-wild exploits.

Add a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use