Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And you are correct. Bug fixes from Valve are few and far inbetween with many bugs being unpatched for years.

https://github.com/ValveSoftware/Source-1-Games/issues/assig...



And that includes security issues; there's one notable vuln where a malicious server or custom map can execute arbitary code on clients. Reported that a few months ago, it's fixed in CS:GO and TF2, but other Valve games apparently aren't receiving fixes (Portal, Portal 2, Left 4 Dead, Left 4 Dead 2, Counter-Strike: Source, HL2DM...)

And that's not to mention the folks who license the Source engine from Valve, who I'm currently trying to contact en masse and get them to fix this (and many other security-critical issues). Apparently, Valve doesn't push security patches downstream to them...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: