4 ms·
Because a deliberate vulnerability is much easier to hide than actual malicious content. One could probably sneak a buffer overflow or use-after-free into a C
by ColonelPhantom 3y ago
Because a deliberate vulnerability is much easier to hide than actual malicious content.
One could probably sneak a buffer overflow or use-after-free into a C project they maintain without being noticed. Actually shipping a trojan is much harder, as observed with the xz-to-sshd backdoor.
- trelane 3y agoAh, so the next stage would have been to add a "bug" in xz that would trigger during the supposedly sandboxed execution, when presented with certain input files. Clever.
- puetzk 3y agoWell, is also quite possible that adding such a bug was the previous stage. Or even just having found one that you didn't report/fix...