• Possibly linux
    link
    fedilink
    English
    1223 days ago

    Is this news worthy? X is the classic example of how a code base becomes completely unmanageable

    • @Mwa@lemm.ee
      link
      fedilink
      English
      122 days ago

      Yeah the original x11 (x windowing system) has not been updated since 2012 (xorg in April 2024) it makes sense

  • @mvirts@lemmy.world
    link
    fedilink
    English
    1223 days ago

    Lol not even reading it because I’ve always assumed that if there’s an RCE on desktop it will inevitably lead to full system compromise.

    😅

    It’s trust all the way down.

  • @Mwa@lemm.ee
    link
    fedilink
    English
    4
    edit-2
    22 days ago

    Considering x windowing system (the original x11) has not been updated since 2012 it makes sense (but xorg popular x11 Implementation was last updated in April 2024)

  • exu
    link
    fedilink
    English
    223 days ago

    I know Phoronix comments, but what’s up with the Linux Mint hate?

    • kamenLady.
      link
      fedilink
      English
      723 days ago

      Tbf, there’s 1 Mint comment and 1 reply to that comment.

  • @d_k_bo@feddit.org
    link
    fedilink
    English
    -623 days ago

    By providing a modified bitmap to the X.Org Server, a heap-based buffer overflow privilege escalation can occur.

    Maybe we should stop writing security critical software in memory unsafe languages. I now this vulnerability was introduced a long time ago, but given that major Wayland compositors are still written in C, something like this isn’t too unlikely to happen again.

    • @superkret@feddit.org
      link
      fedilink
      English
      2123 days ago

      Let’s re-write all currently existing software in Rust, then there will be no more security holes, and every computer will be safe forever.

      • 2xsaiko
        link
        fedilink
        English
        122 days ago

        Everyone knows. There’s nothing to “find out”.

    • @woelkchen@lemmy.world
      link
      fedilink
      English
      423 days ago

      major Wayland compositors are still written in C

      KWin is written in C++ but yes, it’s not a “safe” language.

      something like this isn’t too unlikely to happen again.

      With at least three mainstream implementations – KWin, Mutter, and wlroots – it’s highly unlikely that all would ever be equally affected by one bug.