A Java stack inspection bug
David Wagner <[email protected]>
| Newsgroups | gmane.comp.lang.e.general |
|---|---|
| Message-ID | <[email protected]> |
I thought I would pass along this interesting bug in Java stack inspection: http://slightlyrandombrokenthoughts.blogspot.com/2010/04/java-trusted-method-chaining-cve-2010.html I'm going to guess that this bug has been lurking for maybe a decade or so. I believe that this particular flaw would not arise in an object capability language.