We are at 9 days to the next #curl release and we have only *three* pending CVEs to announce (two low, one medium).
Three is like nothing!
(Mythos says it can't find any more. Zeropath finds no vulnerabilities. Codex security shows an empty list.)
Discussion
We are at 9 days to the next #curl release and we have only *three* pending CVEs to announce (two low, one medium).
Three is like nothing!
(Mythos says it can't find any more. Zeropath finds no vulnerabilities. Codex security shows an empty list.)
@bagder @bert_hubert congrats! So now *all* security bugs are fixed, right? 😁 Is this how it works? 😇 just don’t ship any features afterwords and it‘s perfect! 😆
@bagder And here I am, happy when I make less that 5 spelling errors on a 10 word post...
@bagder Phew, light at the end of the tunnel then. Surprisingly little compared to what oss-fuzz has done to FOSS projects before, but I guess that's because all the easy stuff already got picked up by classic static analysis and fuzzing.
@bagder my friends rave about the Japanese Sakana Fugu model and its ability to find flaws others don’t:
@bagder Any C mistakes in there?
@0xThiebaut one of these three is considered a C mistake (use after free)
I'm under no illusion that the last vulnerability has been found. It just might be that the easy ones are picked now.