CVE-2014-6273: Buffer overflow vulnerability vulnerability in apt-get
lists.debian.org
lists.debian.org
Thanks,
[1] https://launchpad.net/ubuntu/trusty/+source/apt/1.0.1ubuntu2... [2] http://www.ubuntu.com/usn/usn-2353-1/ [3] http://people.canonical.com/~ubuntu-security/cve/2014/CVE-20...
It seems all my default repositories are http, and not https as I had initially assumed, so this seems pretty bad.
Upshot is, apt doesn't need to be served over https because when it fetches Release, it also fetches Release.gpg and verifies the signature contained therein. If it can't fetch or the sig doesn't verify, it squawks.
Spelling out my derp in case someone else had the same thought.
No.
Most buffer overflow exploits likely rely on common patterns in source code (if you ignore variable names). Which could be taught to a computer.
Actually 90% of buffer overflows result in the length of your read and the place of read coming from highly independent sources.
Not to say we'll be able to duplicate biological system levels of computing in silicon, but who knows. Technology is moving pretty damn fast.
We've been saying this for nearly 70 years. I'm still waiting.
The future is already here.
The miniaturization and extension of digital technology into every part of our lives and waking moments is extraordinary. But it's not, by itself, much of a guarantee that we'll see strong AI. It's probably necessary but not sufficient.
AI of this kind is not just the result of a simple step or several. AI will probably be a revolutionary break through that requires an understanding of intelligence and being, we have not made any significant progress in.
But overall I don't think computers will be actively creating things for a while yet. Maybe I just believe to much in humanity, or I'm just to jaded from following tech news for too long.
The crux of the problem is with all medical information Watson has access to only that good. Yet with 1/100th to 1/1000th of the information how is a human doctor better?
Doesn't the NHS sell anonymized data from their health system in the UK? Can't we train Watson off of that data?
Also, ProjectZero...
pwillis@zippy:~$ grep -e "^[[:space:]]\+\(strcpy\|strcat\|sprintf\)" -r apt-1.0.1ubuntu2.1 | wc -l
43
Hmm.https://gist.github.com/AGWA/4069e45856ed261ac0af
You can see the change from a fixed-length buffer to a std::string.
This is apt's Git repo, but the commit hasn't landed there yet: https://anonscm.debian.org/cgit/apt/apt.git/
For example, you can see the change in cdrom: handling code as mentioned in the security notice.
You could also download the package via normal HTTP and install it with dpkg: https://mirrors.ocf.berkeley.edu/debian-security/pool/update... (download the appropriate arch, of course)
If you're deploying lots of wheezy systems, you could also rebuild the cd images (especially the netboot/netinst ones) very easily; the debian-installer docs are very detailed, and there are only a few steps.
Note also that there are discussions for issuing a new release in the near future happening on the mailing list: https://lists.debian.org/debian-release/2014/09/msg00292.htm...
edit: though aptitude depends on libapt-pkg, so quite possibly this bug affects aptitude too :(