Does curl really need bug bounties when 99.999% of the actual risk is users piping output to sudo?
Does curl really need bug bounties when 99.999% of the actual risk is users piping output to sudo?
If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/kajer/statuses/115960911682809000 on your instance and quote it. (Note that quoting is not supported in Mastodon.)