Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Previously (link to upstream announcement): https://news.ycombinator.com/item?id=26426816

No simultaneous source release, a call for users to run Linux benchmarks, and a mysterious tweet about 7Zip source code quality.



It isn't that mysterious.

p7zip has a number of known bugs easily found by fuzzing, as it hasn't seen updates for years. 7-zip in general is a tool that is written in C and supports lots of complex binary formats and thus has a huge attack surface for memory corruption bugs.

This is all pretty obvious with some basic knowledge of how these things work.


Thanks for clarifying, the original tweet has also been expanded innl the same vein: https://mobile.twitter.com/AdmVonSchneider/status/1369300173...

And a bit off-topic, but have you heard of (or maybe commented on) "Bring macOS Quick Look Feature to Windows"[0] aka "parse and preview everything"? Is it paranoia[1] to think "how we defend against parser exploits" should be part of the tool design?

[0] https://github.com/QL-Win/QuickLook

[1] https://news.ycombinator.com/item?id=26007577


The developer has already clarified that the source will be released and open sourced under GNU LGPL - https://sourceforge.net/p/sevenzip/discussion/45797/thread/c...




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: