CVSS scores are such bullshit!
> if you use this Rust library in a clearly wrong way, you will be able to introduce UB into your program without using the `unsafe` keywors
> also this library is a pain to use
CVSS 9.8 critical!
CVSS scores are such bullshit!
> if you use this Rust library in a clearly wrong way, you will be able to introduce UB into your program without using the `unsafe` keywors
> also this library is a pain to use
CVSS 9.8 critical!
@wolf480pl yeah for me CVSS ought to be dropped for better metadata like tags, where there you could /dev/null anything about undefined_behavior (let's be honest, doesn't matters outside of static analysis).
@lanodan a sufficiently ceative compiler can turn any UB into an RCE, but like... researchers should be required to show a PoC of that RCE
@glitch it's more of a "language marketed as idiot-proof turns out to not be idiot-proof"
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.