4 ms·
I don't think that's quite right or at least incomplete. I think that when developing software that runs on many, many platforms different platforms will have d
by cryptarch 10y ago
I don't think that's quite right or at least incomplete. I think that when developing software that runs on many, many platforms different platforms will have different interactions with the software which can sometimes result in bugs.
Sometimes the fault will be with the platforms, e.g. when the bug results from POSIX noncompliance, and sometimes the platform will interact with the program in a valid but unusual way, that isn't covered by the program and thus results in a bug.
- kbenson 10y agoI agree with this, but this isn't what I was referring to. I was referring to things like CVE-2016-7989 which says: On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message sent remotely triggers an unhandled ArrayIndexOutOfBoundsException in Samsung's implementation of the WifiServiceImpl class within wifi-service.jar. This causes the Android runtime to continually crash, rendering the device unusable until a factory reset is performed, a subset of SVE-2016-6542. Note where is says "Samsung's implementation", and specifically mentions that it affects Samsung devices. That's not an android interaction with the hardware platform, that's a completely different company altering the software to market a customized device, and those alterations included vulnerabilities. It's almost like Adobe's vulnerabilities in Acrobat reader being attributed to Microsoft because it runs on Windows.