in reply to Re: Format string vulnerability
in thread Format string vulnerability

I think that putting the blame on webmin, without carefully looking at perl itself is even more damaging to perl that the article in computerweekly. Luckely, perlmonks isn't read by the non-perl-insiders at large, and luckely, p5p was smart enough to do some introspection and not send out a rebuttal.

The security issues are there in Perl, and they are now being addressed. And while webmin isn't free of blame, the issues in Perl make the difference between a denial of service attack (due to the bug in webmin) and comprimising the machine (due to the combined effects of the flaws in webmin and perl).

Perl --((8:>*