Episode 397 - The curl and glibc vulnerabilities
Episode 397 - The curl and glibc vulnerabilities

Episode 397 - The curl and glibc vulnerabilities

Nkechi blessing

34 min
Knowledge
Play

Description

<p dir="auto"><a href="https://infosec.exchange/@joshbressers" rel= "nofollow">Josh</a> and <a href= "https://infosec.exchange/@kurtseifried" rel="nofollow">Kurt</a> talk about a curl and glibc bug. The bugs themselves aren't super interesting, but there are other conversations around the bugs that are interesting. Why don't we just rewrite everything in Rust? Why can't we just train developers to stop writing insecure code. How can AI solve this problem? It's a marvelous conversation that ends on the very basic idea: we already have the security the market demands. Unless we change that demand, security won't change.</p> <h2 dir="auto">Show Notes</h2> <ul dir="auto"> <li><a href= "https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/" rel="nofollow">Curl vulnerability</a></li> <li><a href= "https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so" rel="nofollow">glibc vulnerability</a></li> <li><a href="https://github.com/joshbressers/badge/">Josh's Badge Project</a></li> <li><a href="https://infosec.exchange/@boblord/111211585499765309" rel="nofollow">Bob Lord's phishing message</a></li> </ul>

Uploader

clydeGarden

clydeGarden

Episode 397 - The curl and glibc vulnerabilities - Listen Free | WowFM