Systemd v228 local root exploit
openwall.com
Systemd v228 local root exploit
1–10 of 162 posts
Re: Systemd v228 local root exploit
#2Accurately describes systemd's development over the past few years.
Re: Systemd v228 local root exploit
#3Re: Systemd v228 local root exploit
#4So not only they didn't notice this was exploitable, they also seem to think that a local DoS is not enough for a CVE or a public report. Excellent.
Re: Systemd v228 local root exploit
#5Re: Systemd v228 local root exploit
#6Surprise surprise...
Surprised that software has security flaws? Especially software written in "let-me-use-that-chainsaw-to-trim-the-bushes" C? :)
I know that there will be security flaws in any language, but if there ever was software today that deserved a safer programming language, the init system was it. Or the web browser.
Re: Systemd v228 local root exploit
#7Re: Systemd v228 local root exploit
#8Surprise surprise...
(Future readers can safely ignore the rest of the comment, I was struck by the "did not read the article" disease) Surprised that software has security flaws? Especially software written in "let-me-use-that-chainsaw-to-trim-the-bushes" C? :) I know that there will be security flaws in any language, but if there ever was software today that deserved a safer programming language, the init system was it. Or the web brow…
Re: Systemd v228 local root exploit
#9Earlier quoted context omitted.
(Future readers can safely ignore the rest of the comment, I was struck by the "did not read the article" disease) Surprised that software has security flaws? Especially software written in "let-me-use-that-chainsaw-to-trim-the-bushes" C? :) I know that there will be security flaws in any language, but if there ever was software today that deserved a safer programming language, the init system was it. Or the web brow…
Yeah this issue really has nothing to do with C
Re: Systemd v228 local root exploit
#10>We would like to see that systemd upstream retrieves CVE's themself for their own bugs, even if its believed that its just a local DoS. So not only they didn't notice this was exploitable, they also seem to think that a local DoS is not enough for a CVE or a public report. Excellent.
Some vendors do not consider local DoS as security issues. I tried to discuss these kind of issues in oss-security but even MITRE refused to assign a CVE.