aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorXe Iaso <me@xeiaso.net>2024-06-27 19:38:27 -0400
committerXe Iaso <me@xeiaso.net>2024-06-27 19:38:27 -0400
commit02b513532d1232a0ed8c9f2480b5eaf5d7ead0e9 (patch)
tree684404a6863d68102f098a437247bbfc7ea870b7
parent8c9a7d14a3976605e599c5a14be6b30ed2a8a516 (diff)
downloadxesite-02b513532d1232a0ed8c9f2480b5eaf5d7ead0e9.tar.xz
xesite-02b513532d1232a0ed8c9f2480b5eaf5d7ead0e9.zip
document CVE-2024-28820
Signed-off-by: Xe Iaso <me@xeiaso.net>
-rw-r--r--lume/src/shitposts/no-way-to-prevent-this/CVE-2024-28820.md20
1 files changed, 20 insertions, 0 deletions
diff --git a/lume/src/shitposts/no-way-to-prevent-this/CVE-2024-28820.md b/lume/src/shitposts/no-way-to-prevent-this/CVE-2024-28820.md
new file mode 100644
index 0000000..cdb7ffe
--- /dev/null
+++ b/lume/src/shitposts/no-way-to-prevent-this/CVE-2024-28820.md
@@ -0,0 +1,20 @@
+---
+title: '"No way to prevent this" say users of only language where this regularly happens'
+date: 2024-06-27
+series: "no-way-to-prevent-this"
+type: blog
+hero:
+ ai: "Photo by Andrea Piacquadio, source: Pexels"
+ file: sad-business-man
+ prompt: A forlorn business man resting his head on a brown wall next to a window.
+---
+
+In the hours following the release of [CVE-2024-28820](https://www.tenable.com/cve/CVE-2024-28820) for the project [OpenVPN Auth-LDAP](https://github.com/threerings/openvpn-auth-ldap), site reliability workers
+and systems administrators scrambled to desperately rebuild and patch all their systems to fix a vulnerability where passing fourteen colons into the password field when the attacker knows a valid username, causing a buffer overflow. This is due to the affected components being
+written in C, the only programming language where these vulnerabilities regularly happen. "This was a terrible tragedy, but sometimes
+these things just happen and there's nothing anyone can do to stop them," said programmer King Edmond Wiegand, echoing statements
+expressed by hundreds of thousands of programmers who use the only language where 90% of the world's memory safety vulnerabilities have
+occurred in the last 50 years, and whose projects are 20 times more likely to have security vulnerabilities. "It's a shame, but what can
+we do? There really isn't anything we can do to prevent memory safety vulnerabilities from happening if the programmer doesn't want to
+write their code in a robust manner." At press time, users of the only programming language in the world where these vulnerabilities
+regularly happen once or twice per quarter for the last eight years were referring to themselves and their situation as "helpless."