Samuel Henrique

197 posts

Samuel Henrique

Samuel Henrique

@samueloph_

debian developer, rust, python, security and stuff. he/him

Katılım Şubat 2015
322 Takip Edilen161 Takipçiler
Samuel Henrique
Samuel Henrique@samueloph_·
@FFmpeg @PhantomStnd Pro-tip: if you become a CNA, you get to decide what becomes a CVE. I know it does take some work, but you'll have control.
English
1
0
7
1.2K
FFmpeg
FFmpeg@FFmpeg·
@PhantomStnd It's Google getting the CVEs assigned, not us
English
2
1
161
10.6K
FFmpeg
FFmpeg@FFmpeg·
Here's an example of Google's AI reporting security vulnerabilities in this codec: issuetracker.google.com/issues/4401831… We take security very seriously but at the same time is it really fair that trillion dollar corporations run AI to find security issues on people's hobby code? Then expect volunteers to fix.
FFmpeg@FFmpeg

Patch to fix an issue with decoding LucasArts Smush codec, specifically the first 10-20 frames of Rebel Assault 2, a game from 1995. FFmpeg aims to play every video file ever made.

English
73
106
1.6K
595.4K
Samuel Henrique
Samuel Henrique@samueloph_·
I've published the recordings of two of our #curl activities from Debian 's #debconf25 "wcurl - one year later - DebConf 25" youtube.com/watch?v=RvnDvi… Short presentation about what happened since wcurl’s creation in May 17 2024 and what will happen next.
YouTube video
YouTube
English
1
0
0
195
Samuel Henrique retweetledi
MatLab crashes
MatLab crashes@memecrashes·
MatLab crashes tweet media
ZXX
8
49
604
35.9K
Samuel Henrique
Samuel Henrique@samueloph_·
I've just published a blog post listing exciting new features in Debian 13, focusing on practical changes that can improve your workflow for better performance and productivity. samueloph.dev/blog/debian-13…
English
0
1
1
243
Samuel Henrique
Samuel Henrique@samueloph_·
@odyssjii @HSVSphere no, it goes to 0 because curl vulnerabilities are detected/fixed years after they got introduced, on average.
English
1
0
2
59
Omid Ghavami Zeitooni
Omid Ghavami Zeitooni@odyssjii·
@HSVSphere Notice how it goes down to essentially 0? Yeah, look at the dates — this has a lot more to do with lack of safety mindset because there was no real threat previously.
English
2
0
0
407
HSVSphere
HSVSphere@HSVSphere·
From the curl creator himself: About half of all curl vulnerabilities were caused by C directly, and wouldn't have been possible in any other language.
HSVSphere tweet media
English
19
18
359
21.5K
Тsфdiиg
Тsфdiиg@tsoding·
Time is the Best Unique Identifier
English
36
42
956
44K
Samuel Henrique
Samuel Henrique@samueloph_·
Debian should publish a micronews article about this soon.
English
0
0
0
80
Samuel Henrique
Samuel Henrique@samueloph_·
-- CRITICAL CVE UPDATE FOR DEBIAN-- Fixes for a critical rsync vulnerability (CVE-2024-12084) have been released for Stable/Bookworm, Testing and Unstable. Oldstable/Bullseye is not affected.
English
1
0
5
375
Samuel Henrique
Samuel Henrique@samueloph_·
@the_codedog Put this in your bashrc # Automatically run "ls" after "cd" [[ $- == *i* ]] && function cd { builtin cd "$@" && ls -Ftr1 }
English
0
0
3
277
codedog 💻🚀
codedog 💻🚀@the_codedog·
cd ../ ls cd ../ ls cd ../ ls
codedog 💻🚀 tweet media
Deutsch
173
3.1K
26.9K
729.5K
LaurieWired
LaurieWired@lauriewired·
The half-life of code is an interesting predictor of project quality. Linux, has one of the longest code half-life’s at 6.6 years. WordPress, less than 2. Every software change induces some risk. Repos with numerous "change bursts" have the highest incidence of defects.
LaurieWired tweet media
English
111
560
5.8K
479.3K
Samuel Henrique
Samuel Henrique@samueloph_·
@evilsocket @JeffreyShran Sorry, I didn't mean to sound like I doubt you, just pointing it out as this might be useful for you when discussing the vector
English
1
0
3
791
Simone Margaritelli
Simone Margaritelli@evilsocket·
@samueloph_ @JeffreyShran that was the initial CVSS that someone at redhat suggested, there's been and there's still conversations going on with a lot of confusion mostly due to miscommunication ... i can assure you it's a RCE.
English
1
0
4
931
Simone Margaritelli
Simone Margaritelli@evilsocket·
* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago. * Full disclosure happening in less than 2 weeks (as agreed with devs). * Still no CVE assigned (there should be at least 3, possibly 4, ideally 6). * Still no working fix. * Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot. * Devs are still arguing about whether or not some of the issues have a security impact. I've spent the last 3 weeks of my sabbatical working full time on this research, reporting, coordination and so on with the sole purpose of helping and pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more.
Simone Margaritelli tweet media
English
82
488
2.8K
364.6K
Samuel Henrique
Samuel Henrique@samueloph_·
@evilsocket @JeffreyShran That CVSS vector doesn't look right, I can't say it's wrong because I don't know the details but it looks like the person who scored it doesn't believe it's an RCE.
English
1
0
3
1K
Simone Margaritelli
Simone Margaritelli@evilsocket·
@JeffreyShran honest answer: i have no idea, i don't do vuln research for work and i have really no idea how the CVSS scores are assigned, i literally had to use that web decoder to understand what the redhat guy was talking about
English
2
0
57
13.2K
Simone Margaritelli
Simone Margaritelli@evilsocket·
@samueloph_ @Halxor149 I’ve reached out to 3 of the developers of the project and two people at canonical. Plus I’ve spent a week debugging the issue for them, showing root causes and suggesting fixes. I feel at this point I’ve done my best, will wait the 30 days embargo and then disclose.
English
2
1
2
66
Simone Margaritelli
Simone Margaritelli@evilsocket·
A week after disclosure, no clear timeline for a fix, no clear idea for the fix itself, the developer's been patronizing me from the very beginning, I asked multiple times to request CVEs for (at least) four vulnerabilities and didn't even get an ack ... very close to drop an 0day
English
4
6
32
5.8K
Simone Margaritelli
Simone Margaritelli@evilsocket·
@Halxor149 There're two people from Canonical involved in the conversation and so far they participated constructively to it less than the developer. I would understand if the problem was low impact, but it's not.
English
1
0
2
109
Samuel Henrique
Samuel Henrique@samueloph_·
@evilsocket The previous version was 2.33.0, was the new one a mistake? Looks like it should be 2.40.0, otherwise there's no version comparison logic that will identify the update.
English
2
0
1
186