GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 17-Apr-2025 03:22:22 JST buherator buherator
    Unauthenticated Remote Code Execution in Erlang/OTP SSH

    https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2

    Not much details and unfortunately I don't know much Erlang (yet), but this one seems pretty interesting!

    CVE-2025-32433
    In conversation about a month ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Unauthenticated Remote Code Execution in Erlang/OTP SSH
      ### Summary A serious vulnerability has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SS...
    • pistolero repeated this.
    • Embed this notice
      :blank: (i@declin.eu)'s status on Thursday, 17-Apr-2025 03:22:21 JST :blank: :blank:
      in reply to
      • 
      • pistolero
      @buherator @p @mint more fun dropped, not sure who has the old/sshocial frontends enabled
      In conversation about a month ago permalink
       and pistolero like this.
    • Embed this notice
       (mint@ryona.agency)'s status on Thursday, 17-Apr-2025 03:23:58 JST  
      in reply to
      • :blank:
      • pistolero
      @i @p @buherator Don't think I ever enabled it, I even had to disable Gopher since it calls timeline fetch directly with no ratelimiting, letting anyone with an F5 key DoS the instance.
      In conversation about a month ago permalink
      pistolero likes this.
    • Embed this notice
       (mint@ryona.agency)'s status on Thursday, 17-Apr-2025 03:24:54 JST  
      in reply to
      • 
      • :blank:
      • pistolero
      @i @buherator @p pede make a gopher interface for rebolter
      In conversation about a month ago permalink
      pistolero likes this.
    • Embed this notice
      pistolero (p@fsebugoutzone.org)'s status on Thursday, 17-Apr-2025 03:47:18 JST pistolero pistolero
      in reply to
      • 
      • :blank:
      @i @buherator @mint gat dammit
      In conversation about a month ago permalink
    • Embed this notice
      pistolero (p@fsebugoutzone.org)'s status on Thursday, 17-Apr-2025 03:50:16 JST pistolero pistolero
      in reply to
      • 
      • :blank:
      @mint @buherator @i All right, it's gonna be a weird day.
      In conversation about a month ago permalink
       likes this.
    • Embed this notice
      tsoifan1997 (sysrq@lab.nyanide.com)'s status on Thursday, 17-Apr-2025 05:04:04 JST tsoifan1997 tsoifan1997
      in reply to
      • 
      • :blank:
      • pistolero
      @p @i @buherator @mint pede implement RFC9421 properly please by tuesday #mutualaid
      In conversation about a month ago permalink
      pistolero likes this.
    • Embed this notice
      pistolero (p@fsebugoutzone.org)'s status on Thursday, 17-Apr-2025 05:08:29 JST pistolero pistolero
      in reply to
      • 
      • :blank:
      • tsoifan1997
      @sysrq @buherator @i @mint I had to run /lib/rfc/grabrfc because I didn't have that one.

      Am I implementing it improperly? I basically just copied what Mastodon was doing.

      I am going to shit a thing out related to thread.
      In conversation about a month ago permalink
    • Embed this notice
      tsoifan1997 (sysrq@lab.nyanide.com)'s status on Thursday, 17-Apr-2025 05:34:23 JST tsoifan1997 tsoifan1997
      in reply to
      • 
      • :blank:
      • pistolero
      @p @i @buherator @mint
      I dunno if you are or not I'm just still annoyed over a bug in Erlang that's been fixed for five months now that affects Pleroma.
      In conversation about a month ago permalink
      pistolero likes this.
    • Embed this notice
      pistolero (p@fsebugoutzone.org)'s status on Thursday, 17-Apr-2025 05:35:07 JST pistolero pistolero
      in reply to
      • 
      • :blank:
      • tsoifan1997
      @sysrq @buherator @i @mint

      > I'm just still annoyed over a bug in Erlang that's been fixed for five months now that affects Pleroma.

      Jill Sandwich.
      In conversation about a month ago permalink
    • Embed this notice
      tsoifan1997 (sysrq@lab.nyanide.com)'s status on Thursday, 17-Apr-2025 05:35:11 JST tsoifan1997 tsoifan1997
      in reply to
      • 
      • :blank:
      • tsoifan1997
      • pistolero
      @p @buherator @i @mint
      I don't intend to shut up over it. :facesofautism:
      In conversation about a month ago permalink
      pistolero likes this.
    • Embed this notice
      pistolero (p@fsebugoutzone.org)'s status on Thursday, 17-Apr-2025 05:36:12 JST pistolero pistolero
      in reply to
      • 
      • :blank:
      • tsoifan1997
      @sysrq @buherator @i @mint You say that like shutting up is the sensible strategy.
      gas_the_normies.png
      In conversation about a month ago permalink

      Attachments


      1. https://media.freespeechextremist.com/rvl/full/adf08d7caadeb96580cb8befdfa71e54f220f3ddd0da869d66715442e997e518?name=gas_the_normies.png
    • Embed this notice
      :blank: (i@declin.eu)'s status on Thursday, 17-Apr-2025 05:37:53 JST :blank: :blank:
      in reply to
      • 
      • tsoifan1997
      • pistolero
      @sysrq @p @buherator @mint the rfc wasn't finished by the time mastodon did theirs, so people are forced to ignore the later 13 draft revisions of subtle differences
      In conversation about a month ago permalink
      pistolero likes this.
    • Embed this notice
      pistolero (p@fsebugoutzone.org)'s status on Thursday, 17-Apr-2025 06:41:02 JST pistolero pistolero
      in reply to
      • 
      • :blank:
      @i @mint @buherator The Github link had basically no useful information, but Fyodor never lets you down: https://seclists.org/oss-sec/2025/q2/52
      In conversation about a month ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: seclists.org
        oss-sec: CVE-2025-32433: Unauthenticated Remote Code Execution in Erlang/OTP SSH
        from Fabian Bäumer
    • Embed this notice
      Phantasm (phnt@fluffytail.org)'s status on Thursday, 17-Apr-2025 18:06:30 JST Phantasm Phantasm
      in reply to
      • 
      • :blank:
      • pistolero
      @p @i @buherator @mint Was wondering why I saw 4 OTP releases yesterday in my Inbox. Now I know the answer.
      In conversation about a month ago permalink
      pistolero likes this.
    • Embed this notice
      pistolero (p@fsebugoutzone.org)'s status on Friday, 18-Apr-2025 05:16:50 JST pistolero pistolero
      in reply to
      • 
      • :blank:
      • Phantasm
      @phnt @buherator @i @mint :helpcomputer:
      In conversation about a month ago permalink
      Phantasm likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.