if machine-learning can find all these holes why can't machine-learning write a product from scratch that is flawless?
CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
11–20 of 256 posts
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#12Maybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the latest versions contain many non-CVE bug fixes. But I doubt it, they will lazily backport these patches to create some frankenstein one-off version and be done with it. Before anyone says "tHaT's wHaT sTaBlE iS fOr": they have literally shipped straight-up broke…
The thing to complain about is if the version in testing is ancient.
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#13Maybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the latest versions contain many non-CVE bug fixes. But I doubt it, they will lazily backport these patches to create some frankenstein one-off version and be done with it. Before anyone says "tHaT's wHaT sTaBlE iS fOr": they have literally shipped straight-up broke…
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#14How bad is it if someone infects my home router using such a thing? They can MITM non-encrypted requests, but there are not a lot of those, right? What else can they do, assuming the computers behind the router are all patched up.
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#15if machine-learning can find all these holes why can't machine-learning write a product from scratch that is flawless?
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#16if machine-learning can find all these holes why can't machine-learning write a product from scratch that is flawless?
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#17How bad is it if someone infects my home router using such a thing? They can MITM non-encrypted requests, but there are not a lot of those, right? What else can they do, assuming the computers behind the router are all patched up.
It's definitely bad.
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#18Maybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the latest versions contain many non-CVE bug fixes. But I doubt it, they will lazily backport these patches to create some frankenstein one-off version and be done with it. Before anyone says "tHaT's wHaT sTaBlE iS fOr": they have literally shipped straight-up broke…
They're not going to put a newer version in stable. The way stable gets newer versions of things is that you get the newer version into testing and then every two years testing becomes stable and stable becomes oldstable, at which point the newer version from testing becomes the version in stable. The thing to complain about is if the version in testing is ancient.
FWIW the fixes referenced here are already fixed in trixie: https://security-tracker.debian.org/tracker/source-package/d...
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#19My own MaraDNS has been extensively audited now that we’re in the age of AI-assisted security audits.
Not one single serious security bug has been found since 2023. [1]
The only bugs auditers have been finding are things like “Deadwood, when fully recursive, will take longer than usual to release resources when getting this unusual packet” [2] or “This side utility included with MaraDNS, which hasn’t been able to be compiled since 2022, has a buffer overflow, but only if one’s $HOME is over 50 characters in length” [3]
I’m actually really pleased just how secure MaraDNS is now that it’s getting real in depth security audits.
[1] https://samboy.github.io/MaraDNS/webpage/security.html
Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
#20Maybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the latest versions contain many non-CVE bug fixes. But I doubt it, they will lazily backport these patches to create some frankenstein one-off version and be done with it. Before anyone says "tHaT's wHaT sTaBlE iS fOr": they have literally shipped straight-up broke…