BLUE
Profile banner
DB
David Buchanan
@retr0.id
Reverse Engineering, cryptography, exploits, hardware, file formats, and generally giving computers a hard time. Occasional CTF player. Fediverse: @retr0id@retr0.id Twitter: @David3141593 Web: www.da.vidbuchanan.co.uk/
19.5k followers392 following19.5k posts
DBretr0.id

A high severity vulnerability in curl is due to be announced at 6am UTC, tomorrow: github.com/curl/curl/di... "probably the worst curl security flaw in a long time" 🍿

13

Mmeson.ninja

now we just need another imagemagick vuln to complete the circle

1
JCjcsalterego.bsky.social

incredible run for badger & cURL though

1
PFpfrazee.com

damn, currrl

3
Bcandlej4ck.bsky.social

Daniel's disclosure that some of it is related to a bug in code he wrote over 20 years ago 💀

1
db-user.bsky.social

thanks for the heads up! kicked this over to our researchers (who were distracted by patch Tuesday)

0
CAambignostic.bsky.social

And everyone said “oh shit”

0
MPskywitches.net

What I’m reading is that this is a really good time to go for a walk and breathe autumn air until major patches are pushed out

0
Kpolyrhyth.ms

Do we know if it was exploited in the wild at all before it was found?

2
AJjabsco.cia.fyi

what's the over/under on this being as bad as Shellshock

0
Profile banner
DB
David Buchanan
@retr0.id
Reverse Engineering, cryptography, exploits, hardware, file formats, and generally giving computers a hard time. Occasional CTF player. Fediverse: @retr0id@retr0.id Twitter: @David3141593 Web: www.da.vidbuchanan.co.uk/
19.5k followers392 following19.5k posts