A lot of folks are going to have a bad time with this
https://nvd.nist.gov/vuln/detail/CVE-2023-45853
It’s a critical #CVE in zlib
Except it’s not critical
And doesn’t affect zlib
The whole CVE system is too broken to fix
A lot of folks are going to have a bad time with this
https://nvd.nist.gov/vuln/detail/CVE-2023-45853
It’s a critical #CVE in zlib
Except it’s not critical
And doesn’t affect zlib
The whole CVE system is too broken to fix
@erincandescent @joshbressers Meaning it's also in zlib tarballs and virtually all zlib distro packages (due to software depending on minizip), but it's just not in libz.so.
@lanodan @joshbressers it's in the zlib repo but not zlib the library
I've yet to find minizip in any zlib packages (I'm trying to find it)
But even if it was there, you can make the argue this affects zlib, which is technically correct
But zlib is special, it's in literally every computing device on the planet
This is going to waste literally millions of dollars with people either patching to get rid of the vulnerability absolutists, or justifying why it's not a problem over and over again
Rigidly following rules and policy without exception either means your policy is terrible, or you don't understand what's going on (or both)
Additionally, this shouldn't have a critical severity. So even if your broken policy makes you keep the data in the system, at least mark the severity appropriately
@joshbressers @lanodan @erincandescent We package it in Debian and hence derivatives - it’s not in the zlib binary package but it is shipped as separate binary packages that do have a userbase.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.