lemmy.dudeami.win
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
snaggen@programming.dev to Rust@programming.dev · 1 year ago

Security advisory for the standard library (CVE-2024-24576)

blog.rust-lang.org

external-link
message-square
10
fedilink
  • cross-posted to:
  • technology@lemmy.world
49
external-link

Security advisory for the standard library (CVE-2024-24576)

blog.rust-lang.org

snaggen@programming.dev to Rust@programming.dev · 1 year ago
message-square
10
fedilink
  • cross-posted to:
  • technology@lemmy.world
Security advisory for the standard library (CVE-2024-24576) | Rust Blog
blog.rust-lang.org
external-link
Empowering everyone to build reliable and efficient software.
  • sugar_in_your_tea@sh.itjust.works
    link
    fedilink
    arrow-up
    3
    ·
    edit-2
    1 year ago

    That’s not going to be particularly feasible when generating bindings and other complex build processes. For example, the Qt bindings run shell commands as part of the build.rs. As does gettext-rs.

    So I don’t think it’s unreasonable to think a developer could sneak in an exploit with “temporary code” to improve some part of the build process on Windows.

Rust@programming.dev

rust@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !rust@programming.dev

Welcome to the Rust community! This is a place to discuss about the Rust programming language.

Wormhole

!performance@programming.dev

Credits
  • The icon is a modified version of the official rust logo (changing the colors to a gradient and black background)
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 4 users / day
  • 55 users / week
  • 384 users / month
  • 2.87K users / 6 months
  • 1 local subscriber
  • 7.13K subscribers
  • 556 Posts
  • 3.04K Comments
  • Modlog
  • mods:
  • snowe@programming.dev
  • Ategon@programming.dev
  • EdTheLegendary@programming.dev
  • kahnclusions@programming.dev
  • torcherist@programming.dev
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org