Another round of image bugs: PNG and JPEG XR
lcamtuf.blogspot.com
lcamtuf.blogspot.com
It would be the work of a decade or more to rewrite image parsing, HTML rendering and all the rest of it, but I honestly think it's the only way we're ever going to get decent security.
Interestingly Mozilla are looking at parts of Gecko that could be rewritten in Rust as an early win (instead of rewriting the entire thing) and image decoding comes up pretty often as a candidate.
Now we only depend on the security of compilers and VMs for these languages :)
(Source: I'm one of the "founders" of Servo.)
If the Java plugin itself has security vulnerabilities how can we expect a full browser written in Java to have none?
The Java plugin was the attempt to build a sandbox. The problems occurred because it is vastly easier to build a sandboxed language from the ground up than to sandbox a language with full access.
I don't know if its possible to gradually replace Webkit's components with OCaml...
All code should have mandatory, compiler-enforced integer overflow and bounds checks at the very least.
This has nothing to do with C's imperative, procedural, low-level programming style. It has everything to do with safety.
- Array implicit decay into pointers instead of requiring an explicit "address of" operator
- No bounds checking
- Implicit conversion between enumerations and numeric types
- Implicit conversions between numeric types
- Null terminated strings
Every time I had code in straight C, I made it look like Pascal by validating all the parameters, compiling with all warnings enabled, warnings as errors, using ADTs with no field access to structs.
A static analyzer is also compulsory.
The amount of money caused by bug fixing in developer time, creation of C memory corruption detection tools and paying for them is just endless.
You can deal with null-terminated strings.
You "just" have to be able to prove that all operations ensure a string remains postpended with a null, and doesn't get extended beyond the length of the underlying allocation.
By the time Windows was starting to be developed, UNIX was already established in the industry and was only natural to take ideas from it.
But yeah, eventually it also helped disseminate C. It was by then that I moved from Turbo Pascal into C++.
I am really looking forward that the likes of D, Go, Rust, .NET Native, Ada, ParaSail, Chapel, Java (past v10) and many others help reduce even more the need for C to the same level as Assembly use nowadays.
> Similarly to the previously discussed bugs ... these two were found with afl-fuzz.