The vulnerability, which carries a perfect 10 base severity score, is tracked as CVE-2024-24576. It affects the Rust standard library, which was found to be improperly escaping arguments when invoking batch files on Windows using the Command API.

    • taladar@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      9
      ·
      7 months ago

      But nothing is so secure that it automatically fixes all design flaws in everything it interacts with.

      • whereisk@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        7 months ago

        Absolutely. I merely suggested a contributing factor to answer why media coverage seems so focused on Rust.