{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,17]],"date-time":"2026-08-17T14:56:18Z","timestamp":1786978578716,"version":"build-2736575974"},"reference-count":44,"publisher":"Wiley","issue":"5","license":[{"start":{"date-parts":[[2003,3,28]],"date-time":"2003-03-28T00:00:00Z","timestamp":1048809600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/onlinelibrary.wiley.com\/termsAndConditions#vor"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Softw Pract Exp"],"published-print":{"date-parts":[[2003,4,25]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Buffer overflow vulnerabilities are among the most widespread of security problems. Numerous incidents of buffer overflow attacks have been reported and many solutions have been proposed, but a solution that is both complete and highly practical is yet to be found. Another kind of vulnerability called format string overflow has recently been found and although not as widespread as buffer overflow, format string overflow attacks are no less dangerous.<\/jats:p>\n                  <jats:p>\n                    This article surveys representative techniques of exploiting buffer overflow and format string overflow vulnerabilities and their currently available defensive measures. We also describe our buffer overflow detection technique that range checks the referenced buffers at run\u2010time. We augment executable files with the type information of automatic buffers (local variables and parameters of functions) and static buffers (global variables in the\n                    <jats:italic>data<\/jats:italic>\n                    \/\n                    <jats:italic>bss<\/jats:italic>\n                    section) and maintain the sizes of allocated heap buffers in order to detect an actual occurrence of buffer overflow. We describe a simple implementation with which we currently protect vulnerable copy functions in the C library. Copyright \u00a9 2003 John Wiley &amp; Sons, Ltd.\n                  <\/jats:p>","DOI":"10.1002\/spe.515","type":"journal-article","created":{"date-parts":[[2003,4,1]],"date-time":"2003-04-01T14:05:18Z","timestamp":1049205918000},"page":"423-460","source":"Crossref","is-referenced-by-count":66,"title":["Buffer overflow and format string overflow vulnerabilities"],"prefix":"10.1002","volume":"33","author":[{"given":"Kyung\u2010Suk","family":"Lhee","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Steve J.","family":"Chapin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"311","published-online":{"date-parts":[[2003,3,28]]},"reference":[{"key":"e_1_2_1_2_2","unstructured":"CERT Coordination Center.https:\/\/2.zoppoz.workers.dev:443\/http\/www.cert.org."},{"key":"e_1_2_1_3_2","unstructured":"Bugtraq Mailing List.https:\/\/2.zoppoz.workers.dev:443\/http\/www.securityfocus.com\/archive."},{"key":"e_1_2_1_4_2","unstructured":"WagnerD FosterJS BrewerEA AikenA.A first step towards automated detection of buffer overrun vulnerabilities.Network and Distributed System Security Symposium San Diego CA February2000;3\u201317."},{"key":"e_1_2_1_5_2","doi-asserted-by":"crossref","unstructured":"CowanC WagleP PuC BeattieS WalpoleJ.Buffer overflows: Attacks and defenses for the vulnerability of the decade.Proceedings DARPA Information Survivability Conference and Exposition Hilton Head SC January2000;119\u2013129.","DOI":"10.1109\/DISCEX.2000.821514"},{"key":"e_1_2_1_6_2","unstructured":"Phrack 1996 7 49 Smashing the stack for fun and profit"},{"key":"e_1_2_1_7_2","unstructured":"Mudge. How to Write Buffer Overflows.https:\/\/2.zoppoz.workers.dev:443\/http\/10pht.com\/advisories\/bufero.html[1995]."},{"key":"e_1_2_1_8_2","unstructured":"Phrack 1999 9 55 The frame pointer overwrite"},{"key":"e_1_2_1_9_2","unstructured":"Phrack 2000 10 56 Taking advantage of non\u2010terminated adjacent memory spaces"},{"key":"e_1_2_1_10_2","unstructured":"Solar Designer. Getting around non\u2010executable stack (and fix).Bugtraq Mailing List.https:\/\/2.zoppoz.workers.dev:443\/http\/www.securityfocus.com\/archive\/1\/7480[August1997]."},{"key":"e_1_2_1_11_2","unstructured":"WojtczukR. Defeating solar designer non\u2010executable stack patch.Bugtraq Mailing Listhttps:\/\/2.zoppoz.workers.dev:443\/http\/www.securityfocus.com\/archive\/1\/8470."},{"key":"e_1_2_1_12_2","unstructured":"Phrack 2001 10 58 The advanced return\u2010into\u2010lib(c) exploits: PaX case study"},{"key":"e_1_2_1_13_2","unstructured":"PaX.https:\/\/2.zoppoz.workers.dev:443\/https\/pageexec.virtualave.net."},{"key":"e_1_2_1_14_2","unstructured":"Solar Designer. Non\u2010executable Stack Patch.https:\/\/2.zoppoz.workers.dev:443\/http\/www.openwall.com\/linux."},{"key":"e_1_2_1_15_2","unstructured":"kNoX.https:\/\/2.zoppoz.workers.dev:443\/http\/cliph.linux.pl\/kNoX."},{"key":"e_1_2_1_16_2","unstructured":"TIS. Executable and Linkable Format Version 1.1.ftp:\/\/download.intel.com\/design\/perftool\/tis\/elf11g.zip."},{"key":"e_1_2_1_17_2","unstructured":"Conover M w00w00 Security Team. w00w00 on Heap Overflows.https:\/\/2.zoppoz.workers.dev:443\/http\/www.w00w00.org\/files\/articles\/heaptut.txt[January1999]."},{"key":"e_1_2_1_18_2","unstructured":"RivasJ. Overwriting the .dtors section.https:\/\/2.zoppoz.workers.dev:443\/http\/www.synnergy.net\/downloads\/papers\/dtors.txt."},{"key":"e_1_2_1_19_2","volume-title":"Using and Porting GNU CC (Version 2.95)","author":"Stallman RM","year":"1999"},{"key":"e_1_2_1_20_2","unstructured":"BouchareineP. __atexit in memory bugs\u2014specific proof of concept with statically linked binaries and heap overflows.https:\/\/2.zoppoz.workers.dev:443\/http\/community.corest.com\/\u02dcjuliano\/heap_atexit.txt."},{"key":"e_1_2_1_21_2","unstructured":"Phrack 2000 10 56 Smashing C++ VPTRs"},{"key":"e_1_2_1_22_2","unstructured":"KaempfM. Vudo\u2014An object superstitiously believed to embody magical powers.https:\/\/2.zoppoz.workers.dev:443\/http\/www.synnergy.net\/downloads\/papers\/vudo\u2010howto.txt[2001]."},{"key":"e_1_2_1_23_2","unstructured":"Scut team teso. Exploiting format string vulnerabilities.https:\/\/2.zoppoz.workers.dev:443\/http\/www.team\u2010teso.net\/releases\/formatstring\u20101.2.tar.gz[September2001]."},{"key":"e_1_2_1_24_2","unstructured":"Phrack 2001 10 57 Once upon a free()..."},{"key":"e_1_2_1_25_2","unstructured":"Phrack 2000 10 56 Bypassing StackGuard and StackShield"},{"key":"e_1_2_1_26_2","first-page":"63","volume-title":"Proceedings of the 7th USENIX Security Symposium","author":"Cowan C","year":"1998"},{"key":"e_1_2_1_27_2","unstructured":"StackShield.https:\/\/2.zoppoz.workers.dev:443\/http\/www.angelfire.com\/sk\/stackshield."},{"key":"e_1_2_1_28_2","first-page":"251","volume-title":"Proceedings of the 2000 USENIX Annual Technical Conference","author":"Baratloo A","year":"2000"},{"key":"e_1_2_1_29_2","unstructured":"RSX.https:\/\/2.zoppoz.workers.dev:443\/http\/www.ihaquer.com\/software\/rsx."},{"key":"e_1_2_1_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/178243.178446"},{"key":"e_1_2_1_31_2","first-page":"13","volume-title":"Proceedings of the Third International Workshop on Automatic Debugging","author":"Jones RWM","year":"1997"},{"key":"e_1_2_1_32_2","first-page":"125","volume-title":"Proceedings of the Winter USENIX Conference","author":"Hastings R","year":"1992"},{"key":"e_1_2_1_33_2","first-page":"177","volume-title":"Proceedings of the 10th USENIX Security Symposium","author":"Larochelle D","year":"2001"},{"key":"e_1_2_1_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/193173.195297"},{"key":"e_1_2_1_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/503272.503286"},{"key":"e_1_2_1_36_2","volume-title":"USENIX Annual Technical Conference","author":"Jim T","year":"2002"},{"key":"e_1_2_1_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"e_1_2_1_38_2","first-page":"156","volume-title":"Proceedings 2001 IEEE Symposium on Security and Privacy","author":"Wagner D","year":"1996"},{"key":"e_1_2_1_39_2","first-page":"144","volume-title":"Proceedings 2001 IEEE Symposium on Security and Privacy","author":"Sekar R","year":"1996"},{"issue":"1","key":"e_1_2_1_40_2","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1145\/77606.77608","article-title":"Interprocedural slicing using dependence graphs","volume":"12","author":"Horwitz S","year":"1990","journal-title":"ACM Transactions on Programming Languages and Systems"},{"key":"e_1_2_1_41_2","first-page":"81","volume-title":"Proceedings of the 11th USENIX Security Symposium","author":"Lhee K","year":"2002"},{"key":"e_1_2_1_42_2","unstructured":"ThuemmelA. Analysis of Format String Bugs.https:\/\/2.zoppoz.workers.dev:443\/http\/julianor.tripod.com\/format\u2010bug\u2010analysis.pdf[February2001]."},{"key":"e_1_2_1_43_2","volume-title":"Proceedings of the 10th USENIX Security Symposium","author":"Cowan C","year":"2001"},{"key":"e_1_2_1_44_2","unstructured":"Libformat.https:\/\/2.zoppoz.workers.dev:443\/http\/box3n.gumbynet.org\/\u02dcfyre\/software\/libformat.html."},{"key":"e_1_2_1_45_2","first-page":"201","volume-title":"Proceedings of the 10th USENIX Security Symposium","author":"Shankar U","year":"2001"}],"container-title":["Software: Practice and Experience"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fspe.515","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/spe.515","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,11]],"date-time":"2024-12-11T22:42:00Z","timestamp":1733956920000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/10.1002\/spe.515"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2003,3,28]]},"references-count":44,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2003,4,25]]}},"alternative-id":["10.1002\/spe.515"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1002\/spe.515","archive":["Portico"],"relation":{},"ISSN":["0038-0644","1097-024X"],"issn-type":[{"value":"0038-0644","type":"print"},{"value":"1097-024X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2003,3,28]]}}}