0x0 ( 0x0@programming.dev ) to Programming@programming.dev · 3 years agoCritical Rust flaw enables Windows command injection attackswww.bleepingcomputer.comexternal-linkmessage-square15linkfedilinkarrow-up178cross-posted to: pulse_of_truth@infosec.pub
arrow-up178external-linkCritical Rust flaw enables Windows command injection attackswww.bleepingcomputer.com0x0 ( 0x0@programming.dev ) to Programming@programming.dev · 3 years agomessage-square15linkfedilinkcross-posted to: pulse_of_truth@infosec.pub
minus-squareSekoia ( Sekoia@lemmy.blahaj.zone ) linkfedilinkarrow-up13·3 years agoAlso, the reason this is a CVE is because Rust itself guarantees that calling commands doesn’t evaluate shell stuff (but this breaks that guarantee). As far as I know C/C++ makes no such guarantee whatsoever.
minus-squareButtons ( Buttons@programming.dev ) linkfedilinkEnglisharrow-up10·3 years agoOur bug is their status quo.
Also, the reason this is a CVE is because Rust itself guarantees that calling commands doesn’t evaluate shell stuff (but this breaks that guarantee). As far as I know C/C++ makes no such guarantee whatsoever.
Our bug is their status quo.