2 ms·
> 2/3rds of CVEs are buffer overruns that cause RCE Is this the "70 percent of all security bugs are memory safety issues" article people like to link every ti
by scoutt 4y ago
> 2/3rds of CVEs are buffer overruns that cause RCE
Is this the "70 percent of all security bugs are memory safety issues" article people like to link every time?
If so, it's not 2/3, it's 70%. They are not buffer overruns, but memory issues, and not all can cause remote code execution.
There is no rule that says that fixing bugs is an itch and everybody has to disperately scratch it, and some people can sleep well at night even if they have a few bugs. The rest is FUD in favor of one or another language flavor.
Not all software has a remote endpoint, is connected to internet, has an UI, or process input, etc. C++ and "juggl(ing) double-ended chainsaws on fire" is not the same and is an unfair comparison.