Hacker News new | ask | show | jobs
by jijji 805 days ago
changing the code by one character making it have an int overflow would have been more elegant.... no and the reason I even bring this point up is in early days of hacking into developers machines sometimes you find unpublished integer overflow exploits...
1 comments

Maybe, but xz wasn’t parsing any input in the SSH use-case so that wouldn’t have resulted in an SSH backdoor.