Skip to content

Comment on FreeBSD Foundation Announces Capsicum Framework Projectparent

Comments

Depending on how you set things up you might use one sandbox to perform multiple decompression calls, so the attacker might be able to mangle someone else's data. But yes, if you set up a new sandbox for each inflate you're safe.

Hash the decompressed data and check the result returned by zlib.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.