(评论)
(comments)

原始链接: https://news.ycombinator.com/item?id=43518560

Atop 2.11版本中发现了一个新的漏洞,CVE-2025-31160,该漏洞与堆问题有关。Hacker News的讨论链接指向了之前关于Atop稳定性的担忧。初步反应表明,该漏洞的严重性低于预期,需要启用可选功能才能被利用。然而,一些用户澄清说,虽然守护进程是可选的,但Atop总是尝试本地连接,这可能使其默认情况下容易受到攻击。攻击者可以在预期端口上运行恶意程序,并发送精心构造的字符串以触发溢出。目前讨论中的修复方案是使有问题的功能可选,尽管存在最初的担忧,但这仍然被认为是一种改进。


原文
Hacker News new | past | comments | ask | show | jobs | submit login
CVE-2025-31160 Atop 2.11 heap problems (openwall.com)
18 points by baggy_trough 1 hour ago | hide | past | favorite | 7 comments










Related:

"You might want to stop running atop" - https://news.ycombinator.com/item?id=43477057

"Problems with the heap" - https://news.ycombinator.com/item?id=43485980



It's unfortunate that Unix sockets isn't being used for local connections like this.


Ah, there's the other shoe:)

> optional sources, that have to be activated explicitly.

So only locally exploitable, and you have to enable an optional feature? That's ... honestly better than I was worried that it might be



No. Local but it always tries to connect and the deamon to which it tries to connect is optional, which means that the default is attackable. An attacker can run their own program on the port and send bad strings that will cause an overflow.


The fix is to make it optional.

But yeah, I was anticipating something quite a bit worse.



Did you stop reading at that sentence?


> always tries to connect






Join us for AI Startup School this June 16-17 in San Francisco!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact



Search:
联系我们 contact @ memedata.com