Libxml2 hooldaja loobus erikohtlemisest haavatavuste kõrvaldamisel

Nick Wellnhofer, who maintains the libxml2 library, has announced that he will now treat vulnerabilities as regular bugs. Reports of vulnerabilities will no longer be prioritized and will be fixed as time permits. Information regarding the nature of the vulnerability will be made publicly available immediately, without waiting for a patch to be formed and a fix to be distributed in distributions and operating systems. Nick has also stepped down from his role in maintaining the libxslt library and expressed doubts that anyone will be ready to take on its support.

A note has been added to the libxml2 project description indicating that the library is written by enthusiasts, maintained by a single volunteer, poorly tested, written in a memory-unsafe language, contains numerous vulnerabilities, and is not recommended for processing untrusted data. Security problem reports are to be submitted through the standard public bug tracking system and will be handled like any other bugs. Vulnerabilities will no longer be fixed behind closed doors, and all available information regarding security issues will be published immediately in a public forum, regardless of non-disclosure requirements until a certain date and without delaying the disclosure until a release.

It is expected that the transition to treating vulnerabilities as ordinary bugs will allow Nick to focus on the core work on libxml2 without being interrupted by unforeseen tasks. Currently, Nick spends several hours a week dealing with vulnerability reports and preparing patches, which creates a significant burden given that the maintenance is done solely out of enthusiasm.

It is noted that withholding information about vulnerabilities before updates and metrics like the OpenSSF Scorecard is merely an attempt by large companies to provoke a sense of guilt among maintainers and make them work for free. Imposing additional requirements on volunteer maintainers who work without compensation has been labeled as a detrimental practice.

Niki sõnul ei oma libxml2 teek vajalikku kvaliteeditaset, et seda saaks kasutada brauserites ja operatsioonisüsteemides. Siiski on suured ettevõtted, nagu Apple, Google ja Microsoft, hakanud libxml2 kasutama oma operatsioonisüsteemides ja toodetes. Sellised tegevused on nimetatud vastutustundetuks ning tehtud töö ürituseks sümptomite kõrvaldamiseks, mitte probleemide põhjuste lahendamiseks. Niki arvates oleks projektile parem, kui need ettevõtted lõpetaksid libxml2 kasutamise.

Allikas: opennet.ru

Osta usaldusväärne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid 🔥 Osta usaldusväärne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid | ProHoster