That's a humble take, and you're right, if I was solo coding it's definitely something that could have slipped me by (not that I would ever code anything security related in C let alone put it into production).
But this was a company that sold a product... they should have had a lot more redundancies in place and eyes looking at this all the time..
As someone that started a career coding (and later managing other that code) secure systems mostly in C, I must disagree with the first sentence, haha.
That's a humble take, and you're right, if I was solo coding it's definitely something that could have slipped me by (not that I would ever code anything security related in C let alone put it into production).
But this was a company that sold a product... they should have had a lot more redundancies in place and eyes looking at this all the time..