Login Register


HOLY SHIT GIT MADE A MISTAKE!!!! filter_list
Author
Message
HOLY SHIT GIT MADE A MISTAKE!!!! #1
Server and client side remote code execution through a buffer overflow in all git versions before 2.7.1 (unpublished CVE-2016-2324 and CVE‑2016‑2315).

http://seclists.org/oss-sec/2016/q1/645

Reply

RE: HOLY SHIT GIT MADE A MISTAKE!!!! #2
Thanks for such a cool share!

Reply

RE: HOLY SHIT GIT MADE A MISTAKE!!!! #3
Glad I don't need to use git for anything.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: HOLY SHIT GIT MADE A MISTAKE!!!! #4
Just goes to show that everything has a vulnerability or security risk to some degree.

Something of this nature would be (or should be) fixed/patched pretty quick.
[Image: AD83g1A.png]

Reply

RE: HOLY SHIT GIT MADE A MISTAKE!!!! #5
The owners are humans - and humans make mistake. This isn't shocking.
If you need to get in contact with me, you may do so over ricochet. My identification is: ricochet:j27xararvgnbbnno.

Reply

RE: HOLY SHIT GIT MADE A MISTAKE!!!! #6
(10-09-2016, 11:58 PM)817_091_278 Wrote: The owners are humans - and humans make mistake. This isn't shocking.

I'm pretty electrified to be quite honest.

Reply

RE: HOLY SHIT GIT MADE A MISTAKE!!!! #7
Git is usually my svc of choice, but I don't use it in any production code so this doesn't affect me. Nice share though.

In terms of the logistics, buffer attacks usually take forever to notice. In the case of Heartbleed with OpenSSL for example, it took 20-something years to find and patch.
(This post was last modified: 10-10-2016, 10:01 PM by Inori.)
It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.

Reply







Users browsing this thread: 1 Guest(s)