I read a book about buffer overflow, and it suggest the next to deal with:
Making the stack (and heap) non-executable provides a high degree of protection against many types of buffer overflow attacks for existing programs.
But I don't understand how we can do it - where the execute would take place, if not on the heap or on the stack?