GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 20-Feb-2024 19:20:40 JST daniel:// stenberg:// daniel:// stenberg://

    Hello #MITRE, (regarding CVE-2023-52071)

    Well, first I of course think that the "burden of proof" would be on the person that insists that there is a problem. The one saying that this is a #CVE should provide the necessary details to explain "beyond reasonable doubt" that the identified problem is a vulnerability. There are no such details or explanations provided in the existing CVE. There is nothing there that identifies a vulnerability.

    In conversation Tuesday, 20-Feb-2024 19:20:40 JST from mastodon.social permalink
    • Embed this notice
      daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 20-Feb-2024 19:20:39 JST daniel:// stenberg:// daniel:// stenberg://
      in reply to

      Let me try:

      The claimed issue identifies a bug in curl that

      1. only existed in debug-builds (thus disqualified)

      2. even in debug-builds, a bad access will at worst cause a crash, which is also what assert itself does when triggered. Thus having the same end result. Not a vulnerability.

      3. in most situations, the bad access will not cause any problems at all, even in debug-builds (because the accessed stack memory is readable)

      In conversation Tuesday, 20-Feb-2024 19:20:39 JST permalink
    • Embed this notice
      daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 20-Feb-2024 19:20:39 JST daniel:// stenberg:// daniel:// stenberg://
      in reply to

      My claims can easily be verified and double-checked by simply reading the code. It's not complicated.

      / Daniel

      In conversation Tuesday, 20-Feb-2024 19:20:39 JST permalink
    • Embed this notice
      daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 20-Feb-2024 19:20:40 JST daniel:// stenberg:// daniel:// stenberg://
      in reply to

      I'm convinced someone just grepped commit messages for this and submitted a #CVE and there was nothing and no one that even tried to confirm or check that this was actually legitimate. There was no filter in place and it was incorrectly let through. That's why it should be rejected. Saying it is "disputed" hints that there can be different views on this subject.

      So, you are asking me to explain how this not identified vulnerability is actually not identifying a vulnerability.

      In conversation Tuesday, 20-Feb-2024 19:20:40 JST permalink

      Attachments


Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.