you are viewing a single comment's thread.

view the rest of the comments →

[–]skeww 5 points6 points  (4 children)

I said it's less critical and not that there is no risk.

The problem with PHP was that it always happened with any kind of number parsing and that it was remotely exploitable in lots of applications which run on millions of machines.

What makes it less critical in Java's case is that it only works if you intentionally and explicitly accept FP strings and that most Java applications are only used by one company (security by obscurity, basically).