Mythos Finds a Curl Vulnerability
daniel.haxx.se
Mythos Finds a Curl Vulnerability
1–10 of 298 posts
Re: Mythos Finds a Curl Vulnerability
#2Re: Mythos Finds a Curl Vulnerability
#3"My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing."
It's a good reminder for us all that the competition in this space is rough and lots of more or less subtle marketing is involved.
Re: Mythos Finds a Curl Vulnerability
#4My mind still cannot understand the quality and refinement that's gone into cURL. It really is the perfect example of something done so right, that people barely think twice about.
Re: Mythos Finds a Curl Vulnerability
#5Typo, or is there a spoof I should go read?
Re: Mythos Finds a Curl Vulnerability
#6Putting on my tinfoil-hat: Sooo, the guy who runs the test and delivers the report could just have removed the more interesting bugs and delivered those to any three letter agency?
Re: Mythos Finds a Curl Vulnerability
#7I'm not sure that follows. As noted, curl was already analyzed to death with every tool available; most software isn't at that level.
Re: Mythos Finds a Curl Vulnerability
#8Putting on my tinfoil-hat: Sooo, the guy who runs the test and delivers the report could just have removed the more interesting bugs and delivered those to any three letter agency?
[flagged]
Re: Mythos Finds a Curl Vulnerability
#9> Not particularly “dangerous” I'm not sure that follows. As noted, curl was already analyzed to death with every tool available; most software isn't at that level.
Re: Mythos Finds a Curl Vulnerability
#10> Not particularly “dangerous” I'm not sure that follows. As noted, curl was already analyzed to death with every tool available; most software isn't at that level.
I don't think I understand what you mean, the "not particularly dangerous" comment was in relation to the vulnerability that was found right ? Surely they would know what constitutes a lower severity level.