BoF in glib. > A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
Every single morning this week I've had to wait for Microsoft to go wake up GitHub. I thought it was supposed to be a 24 / 7 service. image
MS advisories are live. Looks like two publicly disclosed and one EITW.
image
Go hack more MCP shit.
RE: Agreed. But a terrible idea does sound fun... :brdThink: View quoted note β†’
RE: https://infosec.exchange/@cR0w/115663720460315600 Still nothing from Cisco... View quoted note β†’
Cisco published a placeholder advisory for the React vuln CVE-2025-55182. They have not finished analyzing any of their products yet so impact has not been determined.
UAF in ImageMagick.