• dgdft@lemmy.world
    link
    fedilink
    English
    arrow-up
    81
    ·
    2 days ago

    Serious answer: They’re low priority bullshit rather than practical security concerns.

    “This method crashes if you intentionally feed it malformed data!!”- type of stuff.

    • jj4211@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      14 hours ago

      Curl guy has written about a couple of these stupid CVEs, for example: https://daniel.haxx.se/blog/2023/09/05/bogus-cve-follow-ups/

      One I recall was that if you asked curl to write out c code example of libcurl usage, you could get it to write out arbitrary code of your choosing. Note that this required you to have write permission and curl and then with your malicious c code, you then had to compile it and make it executable and run it yourself. So a very roundabout way to use curl as a text editor, and they considered it an arbitrary code execution issue, despite not actually executing the code.