Silver's Home
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
@0x0@programming.dev to Programming@programming.dev • 1 year ago

Critical Rust flaw enables Windows command injection attacks

www.bleepingcomputer.com

external-link
message-square
40
fedilink
  • cross-posted to:
  • technology@lemmy.world
133
external-link

Critical Rust flaw enables Windows command injection attacks

www.bleepingcomputer.com

@0x0@programming.dev to Programming@programming.dev • 1 year ago
message-square
40
fedilink
  • cross-posted to:
  • technology@lemmy.world
  • @xmunk@sh.itjust.works
    link
    fedilink
    17•1 year ago

    Now that it has been identified, it should be an easy fix, at least.

    Still, it’s important to remember that Rust is still a relatively young ecosystem and flaws like this exist until we get burned by them.

    • @BatmanAoD@programming.dev
      link
      fedilink
      19•1 year ago

      And in fact it’s not specific to Rust, and Rust is the first language with a fix available. (Thanks to some other comments for pointing this out.) Java has apparently declared it “won’t fix.”

      https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/#appendix-b-status-of-the-affected-programming-languages

    • @bizdelnick@lemmy.ml
      link
      fedilink
      7•1 year ago

      it should be an easy fix

      But it’s not. Have you read the article?

      • @anton@lemmy.blahaj.zone
        link
        fedilink
        1•1 year ago

        I looked at the diff, it’s around 100 lines of new code and a few hundred lines of comments and tests.
        I couldn’t have written it, but there are many smarter people that fixed it after they learned of the problem.

        What also made it easier to fix is that they (sensibly) chose to error on certain strings that can’t be escaped safely.

        • @bizdelnick@lemmy.ml
          link
          fedilink
          1•1 year ago

          It’s not a proper fix, there are still cases when correct escaping is impossible and the function simply returns a error. I don"t know if if this possible at all to escape any string or if it is just because of lack of documentation, but anyway i wouldn’t call this a thing that is easy to fix.

Programming@programming.dev

!programming@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !programming@programming.dev

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person’s post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you’re posting long videos try to add in some form of tldr for those who don’t want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



  • 74 users / day
  • 684 users / week
  • 3.29K users / month
  • 7.49K users / 6 months
  • 20.6K subscribers
  • 2.18K Posts
  • 33.4K Comments
  • Modlog
  • mods:
  • snowe
    cake
  • Ategon
  • @MaungaHikoi@lemmy.nz
  • @UlrikHD@programming.dev
  • BE: 0.19.3
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org