Comment on An unexpected Redis sandbox escape affecting Debian-based distrosparentComments−b1124yBecause all of the issues they've genuinely fixed, security and otherwise, are meaningless.Or are you just basing this on <bad thing> happened, thus all other cases (hundred of thousands of patches) are wrong?−josephcsible4yThis isn't the only time Debian has introduced a serious security vulnerability by changing things in packages. The most notable prior example that comes to mind is CVE-2008-0166.−gmfawcett4yThat's a notable prior example from 14 years ago. I'm not sure you're making a strong argument here!−pgporada4yIt's still relevant for Web PKI work.−yjftsjthsd-h4yHow is it still relevant? Even if certs made with a vulnerable version weren't revoked at the time, wouldn't they would have been rotated by now?−gunapologist994yAnother similar one (perhaps worse!) from the same era: https://jblevins.org/log/ssh-vulnkey−josephcsible4yIsn't that the same one?−gunapologist994yAh, yes, good catch!
Comments
Because all of the issues they've genuinely fixed, security and otherwise, are meaningless.
Or are you just basing this on <bad thing> happened, thus all other cases (hundred of thousands of patches) are wrong?
This isn't the only time Debian has introduced a serious security vulnerability by changing things in packages. The most notable prior example that comes to mind is CVE-2008-0166.
That's a notable prior example from 14 years ago. I'm not sure you're making a strong argument here!
It's still relevant for Web PKI work.
How is it still relevant? Even if certs made with a vulnerable version weren't revoked at the time, wouldn't they would have been rotated by now?
Another similar one (perhaps worse!) from the same era: https://jblevins.org/log/ssh-vulnkey
Isn't that the same one?
Ah, yes, good catch!