Quantcast
Viewing latest article 20
Browse Latest Browse All 50

Answer by R.. GitHub STOP HELPING ICE for Does CVE-2021-42694 affect only compiled code?

"CVE" 2021-42694 does not affect code at all. It affects the systems human beings use to review code and proposed code changes - that is, fancy text editors/IDEs, GitHub pull request and code review workflows, etc. This is a consequence of blindly applying UTR #9 to the entire body of code/patch as a single context, rather than "resolving embedding levels" in an application-specific (in this context, programming-language-specific) manner so that embedding/override controls are not allowed to exert formatting influence across different contexts (comment blocks, quoted strings, etc.) or just not honoring embedding/override control characters at all.


Viewing latest article 20
Browse Latest Browse All 50

Trending Articles