How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]
1–10 of 31 posts
Re: How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]
#2Re: How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]
#3Salient quote below:
>In May 2005, Georgi Guninski published "64 bit qmail fun", three vulnerabilities in qmail (CVE-2005-1513, CVE-2005-1514, CVE-2005-1515):
[snip]
>Surprisingly, we re-discovered these vulnerabilities during a recent qmail audit; they have never been fixed because, as stated by qmail's author Daniel J. Bernstein (in https://cr.yp.to/qmail/guarantee.html):
>>"This claim is denied. Nobody gives gigabytes of memory to each qmail-smtpd process, so there is no problem with qmail's assumption that allocated array lengths fit comfortably into 32 bits."
1. https://www.qualys.com/2020/05/19/cve-2005-1513/remote-code-...
edit: added quote from referenced url
Re: How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]
#4Re: How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]
#5Does anyone know how qmail has fared since this PDF was written in 2007? Did it make it to 2023 without any bugs surfacing?
Re: How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]
#6Does anyone know how qmail has fared since this PDF was written in 2007? Did it make it to 2023 without any bugs surfacing?
Re: How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]
#7Re: How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]
#8Erm, qmail had lots of bugs[1], when compiled for 64-bit processors (lots of integer overflows), but djb pushed back and said 64-bit wasn't supported. If anything, qmail is known as the most annoying MTA to package, since no modifications to the source are permitted, and the application has to be built using a massive patch tree instead. The quirky management daemons required to run qmail were also obnoxious and at o…
Vendors replied to complaints with: “We don’t support those processors”.
No buddy, you don’t support stable software. It’s buggy even on a single core, it’s just less obvious.
Re: How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]
#9Erm, qmail had lots of bugs[1], when compiled for 64-bit processors (lots of integer overflows), but djb pushed back and said 64-bit wasn't supported. If anything, qmail is known as the most annoying MTA to package, since no modifications to the source are permitted, and the application has to be built using a massive patch tree instead. The quirky management daemons required to run qmail were also obnoxious and at o…
It sounds like the Debian packager didn’t follow the instructions. That doesn’t seem like the fault of the software.
Re: How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]
#10The title of the actual paper is "Some thoughts on security after ten years of qmail 1.0". The post currently has the made-up title "How to Write Software with Zero bugs – 25 years after qmail 1.0 – D. Bernstein [pdf]".