Post #2096837
2024-03-30 00:25 UTC
@lispi314 @AndresFreundTec In general this is reasonable, but this there are some clear exceptions for test vectors in cryptographic libraries and compression libraries (which this was).
Replies (1)
-
@lispi314@udongein.xyz 2024-03-30 00:30
@glyph @AndresFreundTec In this case the actual malicious vector was the near-binary injected code in the practical binary of the unaudited autotools vomit (always autoreconf) which was then bundled in the actual binary artifact that was the compromised tarballs. None should have ever been part of the project. As for the test files, I still think that having a hex dump with comments explaining what flaws particular parts test would be desirable in a lot of cases.