I like the clarification:

Let me also touch this subject while talking security problems. This bug, the oldest so far in curl history, was a plain logic error and would not have been avoided had we used another language than C.

Otherwise, about 40% of all security problems in curl can be blamed on us using C instead of a memory-safe language. 50% of the high/critical severity ones.

Almost all of those C mistakes were done before there even existed a viable alternative language – if that even exists now.

  • pastermil
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 month ago

    Technically, it exists, just in pieces. You probably have ingested some of those pieces.