4 ms·
TLDR: presumably 2 y/o (10 Jul '15) segfault bug in stdlib was discovered, fixed and merged into master on the same day on 27 Sept '17. Next release was 12 Okt
by stfwn 8y ago
TLDR: presumably 2 y/o (10 Jul '15) segfault bug in stdlib was discovered, fixed and merged into master on the same day on 27 Sept '17. Next release was 12 Okt '17, 15 days later. OP argues the bug should have been filed into the CVE [0] so that people who run old versions of Rust know about it and can act accordingly.
[0]: https://en.m.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures https://en.m.wikipedia.org/wiki/Common_Vulnerabilities_and_E...
Personally I'd say running old versions of software already means you don't have all bug fixes. I'm sympathetic to the Rust team's argument that if they'd have to test every bug for security vulnerabilities in order to know if they need to submit it to the CVE they wouldn't get much other work done. It's better to offer smooth upgrade paths and advise users to run the latest versions.
- rini17 8y agoThis is the real point that should never be omitted from TLDR: "As a result, Debian Stable still ships vulnerable Rust versions for some architectures. I expect many enterprise users to have vulnerable versions as well."
- stfwn 8y agoI left it out because it seems to me OP was mistaken. Debian Stable ships with Rust 1.24.1, which is well beyond the last vulnerable version 1.20. https://packages.debian.org/stable/rust/ https://packages.debian.org/stable/rust/
- Strom 8y agoThe blog post was published on 2018-08-18. Perhaps Debian stable was shipping some other version back then?
- stfwn 8y agoNo, it doesn't seem like it to me: https://metadata.ftp-master.debian.org/changelogs/main/r/rustc/rustc_1.24.1+dfsg1-1~deb9u4_changelog https://metadata.ftp-master.debian.org/changelogs/main/r/rus...
- rini17 8y agoIt got treated as security fix only after the article was published: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=906585 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=906585 ..this means i386 and these sysadmins who apply only security updates were still affected at that time.
- debiandev 8y agoThe opposite is true: new vulnerabilities can be introduced in new feature releases, while older releases can receive backported security fixes. That means that the level of security of a well maintained stable release train can only increase over time. This is why Debian puts so much effort in freezing and baking the distribution and backporting security fixes.
- stfwn 8y agoGood points, thank you. This did change my perspective.