Beehaw
  • Communities
  • Create Post
  • search
    Search
  • Login
  • Sign Up
0x0 ( 0x0@programming.dev )  to Programming@programming.dev · 3 years ago

Critical Rust flaw enables Windows command injection attacks

www.bleepingcomputer.com

external-link
message-square
15
link
fedilink
  • cross-posted to:
  • pulse_of_truth@infosec.pub
78
external-link

Critical Rust flaw enables Windows command injection attacks

www.bleepingcomputer.com

0x0 ( 0x0@programming.dev )  to Programming@programming.dev · 3 years ago
message-square
15
link
fedilink
  • cross-posted to:
  • pulse_of_truth@infosec.pub
  • onlinepersona ( onlinepersona@programming.dev ) 
    link
    fedilink
    English
    arrow-up
    19
    ·
    3 years ago

    At least it’s not a segfault, buffer overflow, or whatever else plagues C/C++ programs and is not easy to detect.

    Anti Commercial AI thingy

    CC BY-NC-SA 4.0

    • thingsiplay ( thingsiplay@beehaw.org ) 
      link
      fedilink
      arrow-up
      24
      ·
      3 years ago

      But it got a 10/10 on the scoring system by Github.

      The issue isn’t actually too much related to the Rust core language itself, but rather how they handle scripts on Windows platform. So if you don’t have a Windows program that runs Batch scripts, then it doesn’t matter to you. I wonder how common it is to run Batch scripts in Rust?

      • TehPers ( TehPers@beehaw.org ) 
        link
        fedilink
        English
        arrow-up
        8
        ·
        3 years ago

        if you don’t have a Windows program that runs Batch scripts with untrusted arguments

        This only matters when running the scripts with user inputs passed as arguments to the command, which I can’t imagine being remotely common at all.

      • tatterdemalion ( tatterdemalion@programming.dev ) 
        link
        fedilink
        arrow-up
        6
        ·
        3 years ago

        I don’t think my company uses batch scripts anywhere, but if they did, it would probably be in the app installer for Windows or something.

    • Sekoia ( Sekoia@lemmy.blahaj.zone ) 
      link
      fedilink
      arrow-up
      13
      ·
      3 years ago

      Also, the reason this is a CVE is because Rust itself guarantees that calling commands doesn’t evaluate shell stuff (but this breaks that guarantee). As far as I know C/C++ makes no such guarantee whatsoever.

      • Buttons ( Buttons@programming.dev ) 
        link
        fedilink
        English
        arrow-up
        10
        ·
        3 years ago

        Our bug is their status quo.

Programming@programming.dev

programming@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !programming@programming.dev

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person’s post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you’re posting long videos try to add in some form of tldr for those who don’t want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 132 users / day
  • 639 users / week
  • 1.76K users / month
  • 4.18K users / 6 months
  • 449 local subscribers
  • 28.8K subscribers
  • 2.95K Posts
  • 23K Comments
  • Modlog
  • mods:
  • snowe ( snowe@programming.dev ) 
  • Ategon ( Ategon@programming.dev ) 
  • UlrikHD ( UlrikHD@programming.dev ) 
  • bugsmith ( bugsmith@programming.dev ) 
  • Spyro ( Spyro@programming.dev ) 
  • BE: 0.19.15
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code