BSD and Darwin derivatives An ancient (at least 33 years old) stack-overflow bug has been discovered and fixed in yacc, thanks to a new malloc() implementation by Otto Moerbeek. More info and a complete description of the bug can be found here.
It's great that in the course of improving the OS itself, a bug elsewhere was found and fixed.

Given that the bug was in *yacc* (not in OpenBSD itself), it's not surprising that it remained for so long. This fix deserves credit in that even though the bug was outside OpenBSD, it was still fixed when found (not left for someone else to do).

Put it this way - Microsoft have been around for decades too, but despite their tens of billions of dollars (and thousands of programmers), they still haven't come up with an OS that is anywhere near as secure and robust as OpenBSD. Heck, they couldn't even come up with a firewall as good as *pf* ;)

