‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. oefrha · · focus · HN ↗
    Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires a different and potentially harder exploit to develop a full chain). Difference is it&#x27;s easier than ever to turn vulnerabilities into full compromises. At some point we&#x27;ll have to replace all parsers with something at least as safe as <a href="https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;wuffs" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;google&#x2F;wuffs right? Otherwise ImageMagick and co. will just keep giving.
    1. oefrha · · focus · HN ↗
      Btw there are so many &quot;critical&quot; vulnerabilities in libheif I can&#x27;t even tell if I have them all patched. Just awesome.

      <a href="https:&#x2F;&#x2F;github.com&#x2F;strukturag&#x2F;libheif&#x2F;security&#x2F;advisories?query=severity%3Acritical++" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;strukturag&#x2F;libheif&#x2F;security&#x2F;advisories?qu...

      <a href="https:&#x2F;&#x2F;ubuntu.com&#x2F;security&#x2F;notices&#x2F;USN-8649-1" rel="nofollow">https:&#x2F;&#x2F;ubuntu.com&#x2F;security&#x2F;notices&#x2F;USN-8649-1

      <a href="https:&#x2F;&#x2F;ubuntu.com&#x2F;security&#x2F;notices&#x2F;USN-8683-1" rel="nofollow">https:&#x2F;&#x2F;ubuntu.com&#x2F;security&#x2F;notices&#x2F;USN-8683-1

      <a href="https:&#x2F;&#x2F;ubuntu.com&#x2F;security&#x2F;notices&#x2F;USN-8774-1" rel="nofollow">https:&#x2F;&#x2F;ubuntu.com&#x2F;security&#x2F;notices&#x2F;USN-8774-1

      1. Gigachad · · focus · HN ↗
        At this point writing a media file parser in C&#x2F;C++ is absurdly stupid. The same thing happened with libjxl.
        1. masklinn · · focus · HN ↗
          Also libwebp.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.