TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Vulnerability Update: libarchive

66 pointsby utternerdalmost 9 years ago

3 comments

2trill2spillalmost 9 years ago
&gt; Around three months ago, a post was published (mirror) on GitHub&#x27;s Gist service. In the report, multiple vulnerabilities against portsnap, freebsd-update, bspatch, and libarchive were detailed. To this date, FreeBSD has been silent on official mailing lists.<p>Why didn&#x27;t the poster file the bugs in the FreeBSD bug tracker and&#x2F;or contact the FreeBSD security team? Even posting to the mailing list would have been better than posting on some random github page. I don&#x27;t think you can fault the FreeBSD people for not seeing some random post online.
评论 #12245549 未加载
评论 #12246261 未加载
评论 #12245540 未加载
Titanousalmost 9 years ago
If you&#x27;re interested in securing software update systems, check out The Update Framework. TUF is the only system I&#x27;m aware of that has a comprehensive threat model for the problem of securely distributing software updates.<p><a href="https:&#x2F;&#x2F;theupdateframework.github.io" rel="nofollow">https:&#x2F;&#x2F;theupdateframework.github.io</a>
评论 #12245579 未加载
评论 #12245562 未加载
评论 #12245376 未加载
rodgerdalmost 9 years ago
&gt; The libarchive vulnerabilities could allow a malicious third-party to distribute update archives that could place arbitrary files on the filesystem.<p>Why do people keep doing this crap every time they re-invent the packaging wheel? And it&#x27;s particularly awful from something purporting to be more secure than vanilla FreeBSD (which generally purports to be &quot;better engineered&quot; than Linux, where sane behaviour for distributing binaries is a long-solved problem).
评论 #12248768 未加载