Wouldn't whitelisting conforming input be a better approach? I realize it may be more difficult, but wouldn't that be more secure?
Edit: I'm genuinely interested - I always try and whitelist things when I'm building software. Although I have next to no background when it comes to security in particular.
I know it was a different vulnerability - I was asking more whether the same developer(s) was/were responsible, since this seems to be a comment pattern that I'm hearing with regards to the initial response to the vulnerabilities.
Failure to blacklist non-conforming input.
Really, it is that simple and that complicated.