3 ms·
Is there any way to see a diff between the last affected version and the fixed version? I assume that they didn't want to call attention to the fix before user
by function_seven 4y ago
Is there any way to see a diff between the last affected version and the fixed version?
I assume that they didn't want to call attention to the fix before users had time to update. (Don't want to create a race between attackers and defenders)
But now that the this vulnerability is being announced, how do I find out what code or API endpoint was vulnerable?
EDIT: I mean, just the diff between the offending lines of code and the corrected ones. I assume this vulnerability isn't obvious. It hung around for 6 years. And the commit message probably didn't point it out explicitly, because they didn't want to disclose prior to building the release.
If I just diff everything that changed, I'll probably not be able to point and say, "Oh yeah, that line is bad"
- helloooooooo 4y agoBy taking a patched binary and unpatched binary and running them through a diffing tool. There is bindiff, or you can use the Diaphora plugin for IDA Pro, or you can use Ghidra diff correlators.
- tonny747 4y agoThis is open source, so you can just do a diff between version tags in git or github under releases page.
- codetrotter 4y agoThey might not want to draw too much attention to it even now. Otherwise people might know what kind of hints to look for in the future when security issues are being silently fixed. Possibly.
- capableweb 4y agoI'm guessing these two commits (one or both) are related to the CVEs: - https://github.com/home-assistant/supervisor/commit/2ae2d0e1070067b2b47bdfecfb44eca697b964fd https://github.com/home-assistant/supervisor/commit/2ae2d0e1... ("Performance tweaks middleware" but doesn't seem to be about performance but about auth) - https://github.com/home-assistant/supervisor/commit/3d74e07c5e977468611e26a64ad7926a5240e21b https://github.com/home-assistant/supervisor/commit/3d74e07c... ("Backport core api filter" but doing request filtering based on "potential harmful query string") No need to be secretive about it. Updates have been automatically pushed + if someone wanted to see how it was fixed in order to exploit it, they'll be able to browse through the commits just like I did, and probably find it even easier as I'm no pentester, just a casual programmer.
- function_seven 4y agoThank you! This is exactly what I was looking for. That second link seems pretty obvious.
- josephcsible 4y agohttps://github.com/home-assistant/supervisor/commit/3d74e07c5e977468611e26a64ad7926a5240e21b#diff-b87a8d41af603d8f42fbd98aba995716a072ae19d0201db5d91388f53463f7a6R116-R135 https://github.com/home-assistant/supervisor/commit/3d74e07c... Oh dear. This is awful for the same reason that https://thedailywtf.com/articles/Injection_Rejection https://thedailywtf.com/articles/Injection_Rejection is.
- ratorx 4y agoHaven’t read all the code, but If it’s defense in depth, then it seems fine. If it’s the sole protection towards SQL injections, then it seems quite sketchy.