Hacker News (curated)new | past | comments | ask | show | jobs| show hidden

The worst part is that in 2020 they explicitly documented that the remote filename is attacker controlled,but still allowed it to reach system() That is C security 101: never pass untrusted input through a shell. This should have been caught in review!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact | github