GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Friday, 02-May-2025 06:08:59 JST daniel:// stenberg:// daniel:// stenberg://

    We got this "HIGH security problem" in #curl earlier today:

    "The -o / --output parameter in cURL does not restrict or sanitize file paths. When passed relative traversal sequences (e.g., ../../), cURL writes files outside the current working directory, allowing arbitrary file overwrite. In automated or privileged environments (CI/CD, root containers), this leads to Remote Code Execution (RCE), privilege escalation, and supply chain risk."

    Never a dull moment.

    In conversation about 13 days ago from mastodon.social permalink
    • Haelwenn /элвэн/ :triskell: likes this.
    • Phantasm repeated this.
    • Embed this notice
      daniel:// stenberg:// (bagder@mastodon.social)'s status on Friday, 02-May-2025 06:20:59 JST daniel:// stenberg:// daniel:// stenberg://
      in reply to

      Same user followed up with a second severity HIGH security problem.

      "The --capath option in cURL and CURLOPT_CAPATH in libcurl accept any directory path without validation. If an attacker provides a custom CA path containing a fake root certificate, cURL will trust malicious HTTPS endpoints signed with that fake root."

      I'm fortunate to get to work with the best people 🤠

      In conversation about 13 days ago permalink
      feld likes this.
      Peter Krefting repeated this.
    • Embed this notice
      daniel:// stenberg:// (bagder@mastodon.social)'s status on Friday, 02-May-2025 14:58:11 JST daniel:// stenberg:// daniel:// stenberg://
      in reply to
      • Sergio 🏳️‍⚧️ 🏳️‍🌈 :flagBi:

      @sergiotarxz sounds like working as intended

      In conversation about 13 days ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Sergio 🏳️‍⚧️ 🏳️‍🌈 :flagBi: (sergiotarxz@social.owlcode.tech)'s status on Friday, 02-May-2025 14:58:12 JST Sergio 🏳️‍⚧️ 🏳️‍🌈 :flagBi: Sergio 🏳️‍⚧️ 🏳️‍🌈 :flagBi:
      in reply to

      @bagder Sounds like a somebody else problem.

      In conversation about 13 days ago permalink
    • Embed this notice
      Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Friday, 02-May-2025 14:58:29 JST Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
      in reply to
      @bagder Ah yes, high :dudeweed: security problems
      In conversation about 13 days ago permalink
      Phantasm likes this.
    • Embed this notice
      daniel:// stenberg:// (bagder@mastodon.social)'s status on Friday, 02-May-2025 19:51:45 JST daniel:// stenberg:// daniel:// stenberg://
      in reply to

      Both these reports might be AI slop but we can't be sure - they lack some of the most obvious giveaways. People can be stupid without AI as well.

      In conversation about 13 days ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.