in reply to Re: The "Perl Security Problem"?
in thread The "Perl Security Problem"?
However, the fault in the code of webmin (allowing untrusted users to supply the first argument to (s)printf) is much more serious due to the possibility of exploiting a buffer overrun/integer truncation error in Perl.
There is a bug in Perl, and it is good that it is addressed. It's very unprofessional, and IMO, bad for the name of Perl, to not look at this seriously and instantly dismiss it as "not a Perl problem".
Luckely, people on p5p aren't the zealots like you find here, and there they did look further. The result, no false claims being made, and a serious bug getting fixed.
|
|---|