3 ms·
> My understanding of the vulnerability happens because a different process interleaves access to the same object in the file system between the time of check (
by adev_ 3y ago
> My understanding of the vulnerability happens because a different process interleaves access to the same object in the file system between the time of check (TOC) and time of use (TOU) leading to the TOCTOU bug. And this isn't a vulnerability in C++ because it's considered UB by the spec.
The definition as Undefined Behaviour in the spec is quite unfortunate and a mistake. We do agree on that.
> I'm not happy with the CVE system, no one is. You're not either. All I'm saying is, comparisons of CVEs across languages, like Sutter has done, aren't helpful or useful.
On this I do agree too. And saying that a lot of communities have things to learn from the Rust core team about security issue handling is a completely fair statement.
What infuriated me was your point:
> but only because C++ doesn't regard the issue as a problem at all. The problem definitely exists in C++, but it's not acknowledged as a problem, let alone fixed
Which tend to under-mean that the C++ community took no action regarding to this exact problem. When, in fact, it is already patched and released in all major implementations (exactly like Rust did).
- nindalf 3y agoYeah you're right, I originally said no action was taken because I was going off of my recollection of the original issue 2 years ago. When Rust released this blog post (Jan 20th 2022) the same issue had been fixed already in Python. When I asked around about C++, people pasted the reference link and said it didn't need to be fixed because it was defined as UB. I stand corrected, they did fix it. And good on them for fixing it and not closing it as "spec says its fine". It's still bad they didn't file a CVE for it, knowing that other languages did so. It reduces trust in their ecosystem.
- adev_ 3y ago> It's still bad they didn't file a CVE for it, knowing that other languages did so. It reduces trust in their ecosystem. Curiosity question: Do you know if python has also a CVE for this exact same problem ? I am not able to find it back through their git history.
- lifthrasiir 3y agoIn my understanding, no. I believe it was bpo-4489 [1], and I couldn't find a matching advisory from the PSF's database [2] which should contain most historical advisories as well (it does seem to miss earliest advisories like PSF-2005-001 and PSF-2006-001 though). [1] https://github.com/python/cpython/issues/48739 https://github.com/python/cpython/issues/48739 [2] https://github.com/psf/advisory-database/ https://github.com/psf/advisory-database/