‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. oefrha · · focus · HN ↗
    Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires a different and potentially harder exploit to develop a full chain). Difference is it&#x27;s easier than ever to turn vulnerabilities into full compromises. At some point we&#x27;ll have to replace all parsers with something at least as safe as <a href="https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;wuffs" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;wuffs right? Otherwise ImageMagick and co. will just keep giving.
    1. someothherguyy · · focus · HN ↗
      too powerful to give up, sweet imagick love
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.