logoalt Hacker News

bilekastoday at 8:33 AM1 replyview on HN

I'm not sure how that proves I didn't read the article ?


Replies

croontoday at 9:38 AM

Someone external to the curl team ran the test. If that third party found a severe CVE that they could use across all the global curl attack surface, and did not disclose it back to the curl team, the third party could keep using the exploit until discovered independently.