Git: Newline injection in credential helper protocol
bugs.chromium.org
bugs.chromium.org
Malicious URLs may cause Git to present stored credentials to the wrong server - https://github.com/git/git/security/advisories/GHSA-qm7j-c96...
..And the commit that fixed it:
https://github.com/git/git/commit/9a6bbee8006c24b46a85d29e7b...
This is your reminder that there is no such thing as computer security in the year 2020. Treat your computers accordingly.
Hmm, it makes sense to catch the error when writing, but I wonder why not fix the parser as well? https://example.com?foo=bar is a valid URI reference per RFC 3986 and doesn’t look so malicious yet it’s still parsed wrong. (I didn’t bother to track down and read the parser code.)
Unauthorized access to cameras in Safari on macOS and iOS - https://www.ryanpickren.com/webcam-hacking
And another one related to URL parsing:
The unexpected Google wide domain check bypass - https://bugs.xdavidhu.me/google/2020/03/08/the-unexpected-go...
The way we typically use passwords (you just outright tell the other party the password and we hope that's fine) is terrible security design. But everything about passwords is pretty terrible, their only "benefit" is that they're easy which is often undone by measures layered on top to try to deliver security, such as password rotation policies.
But this was still a dumb bug.