oss-sec mailing list archives

Re: Thoughts on Shellshock and beyond


From: Michal Zalewski <lcamtuf () coredump cx>
Date: Thu, 9 Oct 2014 01:24:11 -0700

vendors are not liable, not even for the most serious
software bugs. so there is no incentive for them to make
better software.

On the flip side, would it have been better if, say, Chet could be
sued for millions in damages for the bug in bash?

/mz


Current thread: