Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There's no exploit on the bug report at least, unless you consider the crash reproducer one.




UAF bugs lead to RCE exploit chains.

They can if someone manages to develop an exploit. Let's not confuse vulnerabilities and exploits.

This bug might lead to vulnerability and that's enough. It makes no sense to waste lot of time and research whether it is possible or not - it is faster to remove the buggy codec nobody needs or make a fix.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: