1
1
Fork 0
mirror of https://github.com/pbatard/rufus.git synced 2024-08-14 23:57:05 +00:00
rufus/res
Pete Batard c3c39f7f8a [pki] fix https://www.kb.cert.org/vuls/id/403768
* This commit effectively fixes https://www.kb.cert.org/vuls/id/403768 (CVE-2017-13083) as
  it is described per its revision 11, which is the latest revision at the time of this commit,
  by disabling Windows prompts, enacted during signature validation, that allow the user to
  bypass the intended signature verification checks.
* It needs to be pointed out that the vulnerability ("allow(ing) the use of a self-signed
  certificate"), which relies on the end-user actively ignoring a Windows prompt that tells
  them that the update failed the signature validation whilst also advising against running it,
  is being fully addressed, even as the update protocol remains HTTP.
* It also need to be pointed out that the extended delay (48 hours) between the time the
  vulnerability was reported and the moment it is fixed in our codebase has to do with
  the fact that the reporter chose to deviate from standard security practices by not
  disclosing the details of the vulnerability with us, be it publicly or privately,
  before creating the cert.org report. The only advance notification we received was a
  generic note about the use of HTTP vs HTTPS, which, as have established, is not
  immediately relevant to addressing the reported vulnerability.
* Closes #1009
* Note: The other vulnerability scenario described towards the end of #1009, which
  doesn't have to do with the "lack of CA checking", will be addressed separately.
2017-08-31 12:19:11 +01:00
..
appstore [misc] add static_strcat & static_strcpy and use static_ calls wherever possible 2017-08-10 19:43:52 +01:00
freedos [dos] update FreeDOS 2017-01-13 11:10:52 +00:00
grub [grub] update Grub4DOS to latest 2017-05-15 12:45:03 +01:00
grub2 [grub] update GRUB to 2.02 release 2017-05-05 19:21:53 +01:00
hogger [misc] fix an issue with Far Manager 2014-05-27 02:02:50 +01:00
icon-set [misc] add build data for Windows Apps Store 2017-04-20 12:59:46 +01:00
localization [pki] fix https://www.kb.cert.org/vuls/id/403768 2017-08-31 12:19:11 +01:00
mbr [misc] fix spelling mistakes 2013-06-22 01:15:36 +01:00
syslinux [syslinux] update Syslinux to v6.03 2014-11-11 19:54:05 +00:00
togo [togo] Add Windows To Go support - part 2 2015-01-16 01:53:24 +00:00
uefi v2.10 (build 973) 2016-07-20 10:51:08 +01:00
down.ico [ui] add advanced mode 2012-05-17 22:56:19 +01:00
rufus.ico [ui] improve application look on high DPI displays 2015-05-15 00:36:42 +01:00
rufus.ini [misc] miscellaneous cleanup 2017-04-04 17:26:45 +01:00
up.ico [ui] add advanced mode 2012-05-17 22:56:19 +01:00