CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
lists.thekelleys.org.uk
CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
1–10 of 256 posts
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#2To quote a famous (in certain circles) bowl of petunias, "oh no, not again!"
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#3Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#4To quote a famous (in certain circles) bowl of petunias, "oh no, not again!"
Are you saying this is Arthur Dent's fault? (again)
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#5It's a good thing this software isn't used in millions of devices which almost never receive updates.
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#6It's a good thing this software isn't used in millions of devices which almost never receive updates.
It's more of a good thing that, in most cases, it's on devices that won't send it any packets unless a client first authenticates to a Wi-Fi station or physically plugs into an Ethernet port.
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#7How bad is it if someone infects my home router using such a thing? They can MITM non-encrypted requests, but there are not a lot of those, right?
What else can they do, assuming the computers behind the router are all patched up.
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#8Maybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the latest versions contain many non-CVE bug fixes.
But I doubt it, they will lazily backport these patches to create some frankenstein one-off version and be done with it.
Before anyone says "tHaT's wHaT sTaBlE iS fOr": they have literally shipped straight-up broken packages before, because fixing it would somehow make it not "stable". They would rather ship useless, broken code than something too new. It's crazy.
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#9some of these would have made to embedded hardwares, making updates more challenging if say you were to flash an update.
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#10if machine-learning can find all these holes
why can't machine-learning write a product from scratch that is flawless?