TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

A closer look at recent HTTP/2 vulnerabilities affecting Kubernetes and others

63 点作者 rwestergren超过 5 年前

2 条评论

deathanatos超过 5 年前
CVE writers make me cry sometimes. The original advisory is incredibly light on details, like, what software actually has the bug. The CVEs themselves also fail to adequately describe <i>what</i> is vulnerable. E.g., CVE-2019-9516 “0-Length Headers Leak”, the CVE implicates &quot;Ubuntu&quot;. Ubuntu (probably) can&#x27;t be vulnerable to this CVE, some piece of software <i>on</i> Ubuntu must be; and indeed clicking through to the USN shows that it&#x27;s nginx. But then, why only single out Ubuntu, Debian and Fedora? Surely the others are equally vulnerable?<p>It was the same way w&#x2F; the recent VLC vuln. where the researcher just kinda dumped an ASan output into a bug tracker and &quot;I has a working exploit&quot; and <i>no additional details</i>.
评论 #20875294 未加载
delta1超过 5 年前
Off topic: is it common to hot-link images away from your own site to (in this case) imgur.com ?<p>On a corporate network it means I can read the post, but not see the blocked images.<p>Is it just for the author to save bandwidth on - what appears to be - a wordpress site?
评论 #20876644 未加载
评论 #20876067 未加载