4 ms·
I agree, I actually know one of the guys who discovered the bug and had a talk with him the same week the CVE was released. He seemed very sure that it was simp
by httpsterio 6y ago
I agree, I actually know one of the guys who discovered the bug and had a talk with him the same week the CVE was released. He seemed very sure that it was simply a mistake. While fuzzing has been a thing since the 50s, it wasn't as common to fuzz stuff back when with larger input sets just due to practical issues. You'd be lucky to own a quad core CPU and nobody spent their free time throwing cycles at random Linux package source codes for fun.
Stuff like this goes uncovered all the time. The Ring 0 RISC exploit from 2018 comes to mind at first. It wasn't a whole two years after Shellshock and heartbleed that Google releases their Fuzzing service.