Re: news item: Introduction of app-alternatives/coreutils

Michael Orlitzky <[email protected]>
Newsgroups gmane.linux.gentoo.devel
Message-ID <acF2FCCfBlK-Atvx@mertle>
On 2026-03-22 21:36:51, Eli Schwartz wrote:
> 
> Well, I'm sure you are aware this is entirely the wrong question to ask
> -- instead we should ask whether we KNOW they are insecure, ref. the
> security vulnerability Qualys discovered in uutils rm on which
> oss-security thread you commented. :)

In most cases you confer the benefit of the doubt, but here we have a
reimplementation of sensitive core system utilities, under a different
license (so no snooping), and where there is a long list of behavior-
related security bugs that predate even CVE.

The burden is on them to show that they're not vulnerable to those old
exploits. Otherwise, we won't _know_ one way or the other, because
it's a waste of time for anyone qualified to look.

I haven't looked closely at the uutils rm exploit (see: the previous
sentence), but it sounds like they brought back a vulnerability that
was fixed over 20 years ago. Pros: Creates opportunities for Gentoo
archaeology?

  * https://security.gentoo.org/glsa/200501-38
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.