[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: tarmageddon.png (49 KB, 858x329)
49 KB
49 KB PNG
Oh no rust brothers... this popular abandonware library has Remote Code Execution vulnerability even rust were told to be safe language!
>>
How much do we bet it was some tiny useless library 4 levels deep in the cargo dependency tree?
>>
>dangers of open source abandonware
Bro just fork it and fix the fucking problem?

If anything this is a problem with closed source abandonware
>>
>>106963600
>overstated danger
>overstated impact
>overstated relevance of who's affected
>lame name and logo
that's a "modern" CVE alright.
and of course we already have /g/eets falling for it
>>
>>106963824
RCE is still one that matters. These are the ones that the glowies use to pop boxes of people they don't like. They send you a tar file, you open it and bam they've installed a backdoor. Great job not worrying about CVEs.
>>
great, now all the low-IQ brain damaged rust haters can point to the rare vulnerability and say RuSt NoT sAfE1!!!!

when not a single knowledgeable person has ever said it was a perfect silver bullet. if someone goes out of their way to fuck up then you can introduce a vuln. but nope, the brain damaged will invent their own narratives.

hey guys lets not install locks, doors, windows, or have any sort of shelter because one builder out in fucking alabama didnt install hinges right and one single person got their house broken into!!! <--- thats your logic, fucking idiots
>>
>>106963707
to add to what i wrote in >>106963824
start reading
https://edera.dev/stories/tarmageddon
and you will realize quickly that the exaggeration here borders on lying.
>in the popular async-tar Rust library and its deep lineage of forks, including the widely used tokio-tar.
those crates don't appear to be that popular:
https://crates.io/crates/async-tar/reverse_dependencies
https://crates.io/crates/tokio-tar/reverse_dependencies
https://crates.io/crates/astral-tokio-tar/reverse_dependencies
>This vulnerability impacts major, widely-used projects,
oh shit, IS IT OVER!
>including uv, testcontainers, and wasmCloud.
fucking who? lmao
the only one i ever head of is uv. let's see what they have to say:
>In practice, the impact of this vulnerability is low: only source distributions can be formatted as tar archives, and source distributions execute arbitrary code at build/installation time by definition. Consequently, a parser differential in tar extraction is strictly less powerful than the capabilities already exposed to an attacker who has the ability to control source distributions.
https://github.com/astral-sh/uv/security/advisories/GHSA-w476-p2h3-79g9
-----
this how many "modern" CVEs are. a load of exaggerated bullshit.
>>
>>106963836
see >>106963909
>>
>>106963909
True, they're mostly edge cases. CVEs are like "Your computer will EXPLODE CVSS RATING 8.65" and you read the fine print and it's like "You have to enable the setting 'I'm a stupid fucking idiot' and put it into cum mode when the moon is in its primary lunar orbit"
>>
this is actually a bug in the 13 different tar specifications
>>
>>106963879
>perfect silver bullet
every single rust user have made this claim actually
>>
>>106963600
does this affect GNU tar?
>>
>>106964545
this is neither significant, nor is anything significant affected by it. the tar crate (the relevant rust implementation) is not affected. non-rust implementations are not affected, although they would have their own vulnerabilities/bugs. gnu tar for example had this:
https://www.cve.org/CVERecord?id=CVE-2025-45582



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.