Re: news item: Introduction of app-alternatives/coreutils
Michael Orlitzky <[email protected]>
| Newsgroups | gmane.linux.gentoo.devel |
|---|---|
| Message-ID | <acF2FCCfBlK-Atvx@mertle> |
On 2026-03-22 21:36:51, Eli Schwartz wrote: > > Well, I'm sure you are aware this is entirely the wrong question to ask > -- instead we should ask whether we KNOW they are insecure, ref. the > security vulnerability Qualys discovered in uutils rm on which > oss-security thread you commented. :) In most cases you confer the benefit of the doubt, but here we have a reimplementation of sensitive core system utilities, under a different license (so no snooping), and where there is a long list of behavior- related security bugs that predate even CVE. The burden is on them to show that they're not vulnerable to those old exploits. Otherwise, we won't _know_ one way or the other, because it's a waste of time for anyone qualified to look. I haven't looked closely at the uutils rm exploit (see: the previous sentence), but it sounds like they brought back a vulnerability that was fixed over 20 years ago. Pros: Creates opportunities for Gentoo archaeology? * https://security.gentoo.org/glsa/200501-38