3 ms·
Telegram Desktop is a cross-platform C++ app. What similar remote code execution exploit has existed in the wild for it?
by gitweb 6y ago
Telegram Desktop is a cross-platform C++ app. What similar remote code execution exploit has existed in the wild for it?
- valand 6y agoFYI it's not just PL that factors into security. The engineers, for example.
- coldtea 6y agoThe exact same kind of RCE? https://securelist.com/zero-day-vulnerability-in-telegram/83800/ https://securelist.com/zero-day-vulnerability-in-telegram/83... and others... https://www.notebookcheck.net/Researchers-at-Symantec-discover-media-file-vulnerability-in-WhatsApp-and-Telegram.427741.0.html https://www.notebookcheck.net/Researchers-at-Symantec-discov...
- gitweb 6y agoOne of them requires the user to click run on a file, much like running an EXE. The other, simply saves potentially malicious data to external storage which would then have to be run by a separate malicious third-party app. This are far from RCE exploits that execute immediately without poor user decision making, and Rust is not impervious to security exploits similar to these.
- untog 6y agoC'mon. Just because there is one C++ app without remote exploits doesn't mean all C++ apps are immune.