A high-severity flaw [CVE-2019-9686] in pacman utility—package manager for Arch #Linux—could allow malicious remote...

>A high-severity flaw [CVE-2019-9686] in pacman utility—package manager for Arch #Linux—could allow malicious remote servers (or #MitM attackers, if downloading over HTTP) to execute arbitrary code as root security.archlinux.org/ASA-201903-7 Notably, this bypasses package signature checking
HAHAHAHHAHAHAHHAHAHAHAHHAHAHAH

Attached: minimal.png (1465x1007, 117K)

Other urls found in this thread:

cvedetails.com/top-50-products.php
justi.cz/security/2019/01/22/apt-rce.html
twitter.com/AnonBabble

You just wait till I fix my x!

Attached: 1517093549794.gif (647x363, 650K)

shut up boomer

shut the fuck up boomer

Fucking retard boomer

Ha

>reported 2019-03-11
>fixed 2019-03-01
ok

That's a lot of buzzwords

The boomer in this post is astounding.

have sex

Go play quake, boomer.

Archfags BTFO

Attached: 1549627217422.gif (500x281, 1.63M)

They patched it quickly. Security vulnerabilities happen. Arch isn't even in the top 50. cvedetails.com/top-50-products.php

Never-use-package-managers

Vulnerabilities not found are just 0-day.

Oh look here:
>Remote Code Execution in apt/apt-get
justi.cz/security/2019/01/22/apt-rce.html

based arch keeping us safe before issues even show up

>tldr on top
i already like this guy
he's a pretty cool guy

>"Arch is superior."
*Pacman bites xorg.conf*
>"NOOO PACMAN NOOOO, I NEED TO SHOW EVERYBODY MY ANIME WALLPAPER AND TILING WINDOWS."
>*Xorg.conf error, Archtank cant load i3"
>I-I will fix it in no time
>*Drivers sucessfuly loaded, Mintank now activates DE*
>"HA--HA Priopertiary drivers"
>*Cinnamon DE activated, Mintank ready to operate*
>B-UT CINNAMON IS A BLOAT
>"ArchTank meets unknown error, KERNEL PANIC ACTIVATED"

Attached: e2f94614a2990802cae8eac2bee0cf2e0dfb6a60ed3708fecdf96d7c20590fc7.png (1062x664, 114K)

Install Gentoo.

they don't bother including irrelevant software

Arch doesn't even have an xorg.conf file.

>archtards

>Arch #Linux
>#MitM
woah I didn't know arch devs were twitter trannies

what does malcolm in the middle have to do with twitter?

>This pic
I get the arch part but why is Debian, Red Hat and Ubuntu on some sort of towers? What's the meaning here?

this is autism but lol

lmao

>X uses xorg.conf
>so does arch
>X deprecates xorg.conf in favor of xorg.conf.d
>arch follows
>change got communicated but some idiots just didn't pay attention
>idiots update system
>xorg.conf missing
>brainlet screeches
>recreate xorg.conf
>xorg.conf goes missing again
>NOOOOOOOOOOOOOOOOO
>memes ensue and brainlets can't comprehend the situation
>meanwhile anyone with some intelligence and a custom xorg.conf migrated their xorg.conf to xorg.conf.d
>mfw I never had trouble while watching this shitshow
>mfw there's STILL people that think they should use xorg.conf
This amount of brainlet truly is what makes Jow Forums Jow Forums.

Attached: 1458436908807.png (464x700, 420K)

arch doesn't need security updates because it's not used for anything important, when something big happens the arch devs larp like maintainers but they're not consulted for fixes

to be fair, sanitizing input properly is bloated af and considered harmful.

consider the following input:

Content-Disposition=/../../../../../../..//usr/share/libalpm/hooks/evil.hook


they didn't even fix the problem

>pacman -U over a url
I hope none of you do this

iirc python had a similar issue, that's such an obvious thing to sanitize

OOOOOБЛЯЯЯЯЯЯЯЯЯЯЯЯЯЯЯЯЯ, AХAХAХAХAХAХAХAХA ЛOP B CPAЧECКOЙ ПAHИКE, ЛУУУУУOЛЛЛOЛOЛOЛOLOLOLOLOL!!!11

t. Seething and jelly cuckbian.

Is this "xorg failing on arch" meme real? I use arch, because muh gaymes and I'm an absolute noob at Linux (although I use dwm) and never in my life has X failed me. Where does that meme even come from?

Imagine using Arch

Attached: image.jpg (381x399, 57K)

Install Gentoo

how do you store a null char in a C string?