Hacker News new | past | comments | ask | show | jobs | submit login

If the bug was in a library supply by MS and used by SMB and Samba would use that library then the vulnerability would also be present in Samba. But that isn't the case, Samba re-implements the SMB client/server code in it's own library.

A vulnerability that would transfer between different codebases would be protocol-level because all clients and servers that are to be compliant would have to implement the same protocol(s) and perhaps would easily all write identical state machines. Those kinds of errors are often range errors and logic errors as far as I know, which is a different kind of error as far was I have seen written about this compression bug.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: