Re: [oss-security] blocking weird file names (was: xterm terminal crash due to malicious character sequences in file name)

2025-08-18 Thread Jacob Bachmeyer
On 8/17/25 20:44, David A. Wheeler wrote: [...] I proposed forbidding such characters to POSIX. They *did* add a few mechanisms to POSIX to make it somewhat easier to handle filenames with control characters (e.g., find -print0 and xargs -0). However, although they do not *require* that operati

Re: [oss-security] RSYNC: 6 vulnerabilities

2025-08-18 Thread Alan Coopersmith
On 1/14/25 08:53, Nick Tait wrote: Hello OSS-security, Two independent groups of researchers have identified a total of 6 vulnerabilities in rsync. In the most severe CVE, an attacker only requires anonymous read access to a rsync server, such as a public mirror, to execute arbitrary code on the

[oss-security] CVE-2025-53192: Apache Commons OGNL: Expression Injection leading to RCE

2025-08-18 Thread Arnout Engelen
Severity: moderate Affected versions: - Apache Commons OGNL: all versions Description: ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Og