this post was submitted on 11 Apr 2024
89 points (87.4% liked)

Technology

59174 readers
2122 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 70 points 7 months ago* (last edited 7 months ago) (18 children)

Once again this is not a Rust vulnerability.

This is a Windows vulnerability and Rust is simply the first set of tools to implement a workaround - since Microsoft can't do it without breaking backwards compatibility.

Somehow the narrative has turned into negative PR for Rust when in fact they are handling this vulnerability better than anyone else in the industry.

[–] [email protected] 20 points 7 months ago (12 children)

"The Rust standard library did not properly escape arguments when invoking batch files (with the bat and cmd extensions) on Windows using the Command API,"

If the issue is caused by rust not escaping arguments, and fixed by rust properly escaping arguments, how is it not a rust issue?

[–] [email protected] 12 points 7 months ago (5 children)

If the issue is caused by rust not escaping arguments

That Windows API is terrible. There isn't a way to have the escaping done for you. Further, there is not an API where you do not need to do the escaping. There is no documentation on what kind of escaping is needed.

It's not a Rust problem.

[–] [email protected] 4 points 7 months ago (1 children)

The Windows API is the direct access to OS functions. If you're using the API it's your responsibility to do it securely and protect your users.

load more comments (3 replies)
load more comments (9 replies)
load more comments (14 replies)