This Week in Security: AI is Terrible, Ransomware Wrenches, and Airdrop

So first off, go take a look at this curl bug report. It’s a 8.6 severity security problem, a buffer overflow in websockets. Potentially a really bad one. But, it’s bogus. Yes, a strcpy call can be dangerous, if there aren’t proper length checks. This code has pretty robust length checks. There just doesn’t seem to be a vulnerability here.


This is a companion discussion topic for the original entry at https://hackaday.com/2024/01/12/this-week-in-security-ai-is-terrible-ransomware-wrenches-and-airdrop/