TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

An in-depth look at CVE-2018-8878 or why integer overflows are still a thing

3 点作者 jbaviat大约 7 年前

1 comment

jbaviat大约 7 年前
As a former security researcher, I am amazed that integer overflows are still a thing in 2018, in the Ruby core - so probably everywhere... About 10 years ago, integer overflow vulnerabilities were trending in the security community. Plenty of nice vulnerabilities and exploits have been found with them - like in all PDF readers, ... I guess when the momentum of such vulnerabilities goes down, this class of bugs goes unnoticed. Secure programming is hard, it's too bad we don't keep the learning we had in the past.