CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog()
qualys.com
qualys.com
> 2023-12-07: While reviewing this patch, we discovered two more minor vulnerabilities in the same function (an off-by-one buffer overflow and an integer overflow). We immediately sent an analysis, proof of concept, and patch proposal to Red Hat Product Security, and suggested that we directly involve the glibc security team.
I hope my children will see the day when these kinds of software vulnerabilities only exist in "legacy" software.
We regret to inform you your children were killed by an AI using a memory unsafe language"
"This shouldn't have happened: A vulnerability postmortem "
https://googleprojectzero.blogspot.com/2021/12/this-shouldnt...
Relevant quote,
"All of the NSS fuzzers are represented in combined coverage metrics by oss-fuzz, rather than their individual coverage. This data proved misleading, as the vulnerable code is fuzzed extensively but by fuzzers that could not possibly generate a relevant input."
Saying "important software should be rigorously tested" isn't an excuse, it's an actionable and reasonable suggestion. Tut-tutting about implementation language choice in (literally) the platform C runtime is quite a bit less so.
Grandparent was being helpful, basically. You're just sniping.
Exhaustive testing tops out at about two float 32s[0], so of course do that for small functions, but for full application testing type checks are much cheaper.
[0] https://randomascii.wordpress.com/2014/01/27/theres-only-fou...
"A consequence of this principle is that every occurrence of every subscript of every subscripted variable was on every occasion checked at run time against both the upper and the lower declared bounds of the array. Many years later we asked our customers whether they wished us to provide an option to switch off these checks in the interests of efficiency on production runs. Unanimously, they urged us not to--they already knew how frequently subscript errors occur on production runs where failure to detect them could be disastrous. I note with fear and horror that even in 1980 language designers and users have not learned this lesson. In any respectable branch of engineering, failure to observe such elementary precautions would have long been against the law."
-- C.A.R Hoare's "The 1980 ACM Turing Award Lecture"
Thankfully the powers of the law are finally taking attention to it, after a couple of decades since that speech took place.
Recent discussion: https://news.ycombinator.com/item?id=38690597
The good news: the day will come when this kind of software vulnerability will only exist in legacy software.
The bad news: we’ll still be using legacy software at that time.