CIRCL / Circlean

USB key cleaner
https://www.circl.lu/projects/CIRCLean/
BSD 3-Clause "New" or "Revised" License
452 stars 70 forks source link

Master issue for THARD-2 #28

Open Rafiot opened 9 years ago

Rafiot commented 9 years ago

Review of the attack surface on the rPI (e.g. power analysis)

Rafiot commented 8 years ago

https://github.com/CIRCL/Circlean/blob/master/doc/Technical_Notes/TNO_Raspi_boot.pdf

moshekaplan commented 7 years ago
Rafiot commented 7 years ago

I didn't see any recent vulnerability in libmagic allowing command execution. Do you have references?

Fake MIMEtype is assumed, we use it for information and cross check with the extension of the file (see polyglot files).

moshekaplan commented 7 years ago

Unfortunately, this is the only reference I could find : https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-1606 , but it only has DoS and no code execution.