Everyone, get your update hats on immediately; we’re at DEFCON 1

  • SteleTrovilo@beehaw.org
    link
    fedilink
    English
    arrow-up
    5
    ·
    14 hours ago

    According to the last paragraph, the vulnerability is in reading the archive itself, not the decompressed contents.

    • Kactus@piefed.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 hours ago

      I think what quick snail is saying is that if you are going to download a malicious zip file you are just as likely to unzip the archive and run the program inside. It’s a lot easier to just have a malicious payload inside the archive.