over the weekend we did:
hackerone_count += 2;
Now at 142 submissions this year so far for #curl. Out of which 8 were confirmed actual vulnerabilities.
Post
over the weekend we did:
hackerone_count += 2;
Now at 142 submissions this year so far for #curl. Out of which 8 were confirmed actual vulnerabilities.
@bagder Interesting! Thanks for sharing. Sequoia received 74 reports this year on yeswehack and we've confirmed 6 vulnerabilities. Of those, none were serious. Two had to do with wasting resources on specially crafted input. Two were out of bounds array accesses that result in a panic (we're using rust). One was a terminal injection, because we forgot to escape attacker controlled data that we print. And the last one was forgetting to check that the value returned from malloc is not NULL.
@bagder
how many of the not-actually-vulns were good-faith or otherwise helpful?
@wolf480pl 32 of them were marked "informative", means typically means they identified a bug - just not a vulnerability or security problem
@bagder Interesting. Even when removing the AI slop count from the tallies, this year has the worst ratio of actual vulns to reports.
Do you have insights as to why that is?
@bagder Sloppy work by the submitters. (In the traditional, but maybe also in the modern sense)
A space for Bonfire maintainers and contributors to communicate