Live data from Hacker News

Systemd v228 local root exploit

openwall.com

1–10 of 162 posts

Re: Systemd v228 local root exploit

#4
>We would like to see that systemd upstream retrieves CVE's themself for their own bugs, even if its believed that its just a local DoS.

So not only they didn't notice this was exploitable, they also seem to think that a local DoS is not enough for a CVE or a public report. Excellent.

Re: Systemd v228 local root exploit

#6
post #3

Surprise surprise...

(Future readers can safely ignore the rest of the comment, I was struck by the "did not read the article" disease)

Surprised that software has security flaws? Especially software written in "let-me-use-that-chainsaw-to-trim-the-bushes" C? :)

I know that there will be security flaws in any language, but if there ever was software today that deserved a safer programming language, the init system was it. Or the web browser.

Re: Systemd v228 local root exploit

#8
post #6
post #3

Surprise surprise...

(Future readers can safely ignore the rest of the comment, I was struck by the "did not read the article" disease) Surprised that software has security flaws? Especially software written in "let-me-use-that-chainsaw-to-trim-the-bushes" C? :) I know that there will be security flaws in any language, but if there ever was software today that deserved a safer programming language, the init system was it. Or the web brow…

Yeah this issue really has nothing to do with C

Re: Systemd v228 local root exploit

#9
post #6

Earlier quoted context omitted.

(Future readers can safely ignore the rest of the comment, I was struck by the "did not read the article" disease) Surprised that software has security flaws? Especially software written in "let-me-use-that-chainsaw-to-trim-the-bushes" C? :) I know that there will be security flaws in any language, but if there ever was software today that deserved a safer programming language, the init system was it. Or the web brow…

Yeah this issue really has nothing to do with C

It's not the logic of hammering my own fingers that is flawed, it is my choice of a hammer!

Re: Systemd v228 local root exploit

#10
post #4

>We would like to see that systemd upstream retrieves CVE's themself for their own bugs, even if its believed that its just a local DoS. So not only they didn't notice this was exploitable, they also seem to think that a local DoS is not enough for a CVE or a public report. Excellent.

> they also seem to think that a local DoS is not enough for a CVE

Some vendors do not consider local DoS as security issues. I tried to discuss these kind of issues in oss-security but even MITRE refused to assign a CVE.

Post reply on HN