Comment on An unexpected Redis sandbox escape affecting Debian-based distrosparentComments−josephcsible4yThis isn't the only time Debian has introduced a serious security vulnerability by changing things in packages. The most notable prior example that comes to mind is CVE-2008-0166.−gmfawcett4yThat's a notable prior example from 14 years ago. I'm not sure you're making a strong argument here!−pgporada4yIt's still relevant for Web PKI work.−yjftsjthsd-h4yHow is it still relevant? Even if certs made with a vulnerable version weren't revoked at the time, wouldn't they would have been rotated by now?−gunapologist994yAnother similar one (perhaps worse!) from the same era: https://jblevins.org/log/ssh-vulnkey−josephcsible4yIsn't that the same one?−gunapologist994yAh, yes, good catch!
Comments
This isn't the only time Debian has introduced a serious security vulnerability by changing things in packages. The most notable prior example that comes to mind is CVE-2008-0166.
That's a notable prior example from 14 years ago. I'm not sure you're making a strong argument here!
It's still relevant for Web PKI work.
How is it still relevant? Even if certs made with a vulnerable version weren't revoked at the time, wouldn't they would have been rotated by now?
Another similar one (perhaps worse!) from the same era: https://jblevins.org/log/ssh-vulnkey
Isn't that the same one?
Ah, yes, good catch!