@harrysintonen@infosec.exchange
Post #4276425
2026-07-31 11:15 UTC
Last night I "discovered" a vulnerability in a very widely used open-source tool. The tool is nearly 40 years old, and the vulnerability is at least 28 years old.
Interestingly, Apple has a fix included that dates it back to 2008, but it appears for whatever reason the fix never made it to upstream.
Result? Everyone else is vulnerable today. I am not pointing fingers here, but clearly something went wrong.
I've now reported the issue upstream, which will hopefully eventually lead to a fix being distributed to every affected platform.
I am not going to disclose the details of the vulnerability right now, even though the fix has been public for a very, very long time now. As far as I can tell, most Linux and BSD systems are vulnerable right now, so letting coordinated disclosure happen only makes sense.
#infosec #cybersecurity #vulnerabilityresearch
Replies (0)
No replies.