Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> This bug only affects people who dont care about security.

And those running code written by people who don't know any better...

If you are an admin for servers running third part code that you have not verified every line of, you need to be concerned about anything like this just in case said code does something that isn't considered best practise.

Also if the CGI code path uses affected functions, you are not going to be protected by avoiding using them in the code that is eventually called.



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: