programming.dev
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
snaggen to Rust · 1 year ago

Security advisory for the standard library (CVE-2024-24576)

blog.rust-lang.org

external-link
message-square
10
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
49
external-link

Security advisory for the standard library (CVE-2024-24576)

blog.rust-lang.org

snaggen to Rust · 1 year ago
message-square
10
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
Security advisory for the standard library (CVE-2024-24576) | Rust Blog
blog.rust-lang.org
external-link
Empowering everyone to build reliable and efficient software.
  • Schmeckinger@feddit.de
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    But there is no reason to use a script, when you have a build.rs anyways. Since pretty much everything the script can do build.rs can do better.

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      1 year ago

      That’s not going to be particularly feasible when generating bindings and other complex build processes. For example, the Qt bindings run shell commands as part of the build.rs. As does gettext-rs.

      So I don’t think it’s unreasonable to think a developer could sneak in an exploit with “temporary code” to improve some part of the build process on Windows.

Rust

rust

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Welcome to the Rust community! This is a place to discuss about the Rust programming language.

Wormhole

[email protected]

Credits
  • The icon is a modified version of the official rust logo (changing the colors to a gradient and black background)
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 177 users / week
  • 386 users / month
  • 2.89K users / 6 months
  • 1.47K local subscribers
  • 6.91K subscribers
  • 995 Posts
  • 4.71K Comments
  • Modlog
  • mods:
  • snowe
  • Ategon
  • EdTheLegendary
  • kahnclusions
  • torcherist
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org