‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. pixl97 · · focus · HN ↗
    >Interestingly, the vulnerable code had been changed upstream the previous year, but the commit was not documented as a security fix and received no CVE.3 This might be a reason why Debian 12 and 13 have not received the security relevant backports in time.

    Ooof, keeping packages like this up to date with the rate of updates and churn is a mess.

    1. dbgrman · · focus · HN ↗
      If its just tedious, I bet there is room for agentic/automation to keep things tidy.
      1. croemer · · focus · HN ↗
        Which is presumably why Debian developers voted to allow responsible use of LLMs.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.