Ed,
>I don't think we can represent that number with a ULONG!
Maybe when the Merced ships...
>All this because someone had a pointer to a structure (the structure is 700 bytes long), and needed 41st byte of the strucutre. So rather than looking up the name of the structure member or recasting the pointer, he just added 41 to the pointer...and walked off the end of the heap. *sigh*
What you mean it wasn't an array of at least 41 structs? *g*