3 ms·
Do you have any evidence that this would provide security improvements besides the heuristic of reducing surface area? Have there been past exploits?
by jackblemming 4y ago
Do you have any evidence that this would provide security improvements besides the heuristic of reducing surface area? Have there been past exploits?
- rwmj 4y agoCVE-2013-0249 (in the qemu curl driver) was an exploit where the entire qemu process could be exploited because of a bug in curl's SASL driver, which could be invoked remotely by redirecting an http[s]:// URL initiated by qemu. This was fixed by changing qemu to use CURLOPT_PROTOCOLS(3) (as I detailed in my initial posting above) so that curl wouldn't try to redirect to SASL connections starting from an initial HTTP request. IMHO it would be a lot better instead of having to change every possible curl client, to have some kind of distro-level limit on what code might be run by curl. Of course I would still say if you're using curl, you really must use CURLOPT_PROTOCOLS or have a good excuse why not. The above change is just a backstop.