TARmageddon (CVE-2025-62518): RCE Vulnerability Highlights the Challenges of Open Source Abandonware | Edera Blog

https://edera.dev/stories/tarmageddon

4 points · 3 comments · view on lemmy.world

3 Comments

magikmw@piefed.social · 2 pts · 324d (1 reply)

Honestly, cargo could flag crates with known CVEs, be a better package manager.

mandatstory@lemmy.world · 1 pts · 324d
[ removed ]
DeltaWingDragon@sh.itjust.works · 2 pts · 324d

Does this affect GNU tar, or Busybox tar, or BSD tar?

MTK@lemmy.world · 1 pts · 322d

The title seems like a stupid attack on open source.. Because closed source abandonware is not a security issue??

At least open source projects can be forked and updated, a closed source system would leave you with only the option of choosing between the software or security.