|
|
|
|
|
by rwmj
5027 days ago
|
|
Yes it does - qemu-img is written in C. The two programs we found exploitable were written in Python and C. They are written in "satisfactory" languages. Bash is not involved. Yet both suffer exploits because of \n (and other) characters in filenames. |
|
It is a programming error, not an inherent flaw in the language.