Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
josephcsible
4y ago
0 comments
Save
Share
This isn't the only time Debian has introduced a serious security vulnerability by changing things in packages. The most notable prior example that comes to mind is CVE-2008-0166.
0 comments
6 comments · 2 top-level
top
newest
oldest
gmfawcett
4y ago
· 2 in thread
That's a notable prior example from
14 years ago
. I'm not sure you're making a strong argument here!
pgporada
4y ago
It's still relevant for Web PKI work.
yjftsjthsd-h
4y ago
How is it still relevant? Even if certs made with a vulnerable version weren't revoked at the time, wouldn't they would have been rotated by now?
gunapologist99
4y ago
· 2 in thread
Another similar one (perhaps worse!) from the same era:
https://jblevins.org/log/ssh-vulnkey
josephcsible
OP
4y ago
Isn't that the same one?
gunapologist99
4y ago
Ah, yes, good catch!
j
/
k
navigate · click thread line to collapse