My Lemmy Oracle
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
snaggen@programming.dev to Rust@programming.dev · 1 year ago

Security advisory for the standard library (CVE-2024-24576)

blog.rust-lang.org

external-link
message-square
15
fedilink
  • cross-posted to:
  • [email protected]
49
external-link

Security advisory for the standard library (CVE-2024-24576)

blog.rust-lang.org

snaggen@programming.dev to Rust@programming.dev · 1 year ago
message-square
15
fedilink
  • cross-posted to:
  • [email protected]
Security advisory for the standard library (CVE-2024-24576) | Rust Blog
blog.rust-lang.org
external-link
Empowering everyone to build reliable and efficient software.
  • sugar_in_your_tea@sh.itjust.works
    link
    fedilink
    arrow-up
    3
    ·
    edit-2
    1 year ago

    That’s not going to be particularly feasible when generating bindings and other complex build processes. For example, the Qt bindings run shell commands as part of the build.rs. As does gettext-rs.

    So I don’t think it’s unreasonable to think a developer could sneak in an exploit with “temporary code” to improve some part of the build process on Windows.

Rust@programming.dev

rust@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Welcome to the Rust community! This is a place to discuss about the Rust programming language.

Wormhole

[email protected]

Credits
  • The icon is a modified version of the official rust logo (changing the colors to a gradient and black background)
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 6 users / day
  • 55 users / week
  • 389 users / month
  • 2.88K users / 6 months
  • 1 local subscriber
  • 7.14K subscribers
  • 935 Posts
  • 4.43K Comments
  • Modlog
  • mods:
  • snowe@programming.dev
  • Ategon@programming.dev
  • EdTheLegendary@programming.dev
  • kahnclusions@programming.dev
  • torcherist@programming.dev
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org