Skip to content

Comment on An unexpected Redis sandbox escape affecting Debian-based distrosparent

Comments

Because all of the issues they've genuinely fixed, security and otherwise, are meaningless.

Or are you just basing this on <bad thing> happened, thus all other cases (hundred of thousands of patches) are wrong?

This isn't the only time Debian has introduced a serious security vulnerability by changing things in packages. The most notable prior example that comes to mind is CVE-2008-0166.

That's a notable prior example from 14 years ago. I'm not sure you're making a strong argument here!

It's still relevant for Web PKI work.

How is it still relevant? Even if certs made with a vulnerable version weren't revoked at the time, wouldn't they would have been rotated by now?

Another similar one (perhaps worse!) from the same era: https://jblevins.org/log/ssh-vulnkey

Isn't that the same one?

Ah, yes, good catch!

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.