My Lemmy Oracle
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Harry Sintonen@infosec.exchange to Cybersecurity@fedia.io · 9 months ago

#cURL doesn't validate SSH host identity if known_hosts file is missing. I think this is a #vulnerability, but the project disagrees. Advisory is here:

message-square
message-square
5
fedilink
14
message-square

#cURL doesn't validate SSH host identity if known_hosts file is missing. I think this is a #vulnerability, but the project disagrees. Advisory is here:

Harry Sintonen@infosec.exchange to Cybersecurity@fedia.io · 9 months ago
message-square
5
fedilink

#cURL doesn’t validate SSH host identity if known_hosts file is missing. I think this is a #vulnerability, but the project disagrees. Advisory is here: https://sintonen.fi/advisories/curl-ssh-insufficient-host-identity-verification.txt

#infosec #cybersecurity #nocve

  • Harry Sintonen@infosec.exchangeOP
    link
    fedilink
    arrow-up
    2
    ·
    9 months ago

    @[email protected] Curl will likely address this eventually even though they don’t consider it a vulnerability. See https://github.com/curl/curl/issues/16197

Cybersecurity@fedia.io

cybersecurity@fedia.io

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

  • Be kind
  • Limit promotional activities
  • Non-cybersecurity posts should be redirected to other communities within infosec.pub.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 1 user / month
  • 925 users / 6 months
  • 1 local subscriber
  • 1 subscriber
  • 1.58K Posts
  • 901 Comments
  • Modlog
  • mods:
  • shellsharks@fedia.io
  • tweedge@fedia.io
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org