SO CSharp
81 subscribers
1.43K photos
73 videos
80 links
Some stuff about about software development and related (devops, cs, ai, etc.). Stolen memes (mostly), some rare #random_PoK (random Piece of Knowledge), stream notifications. Also #weekendmeme
Download Telegram
😁7πŸ‘1
Been there...

#hardware
😁8πŸ‘1
#fridaymeme 😁😁😁
😁6πŸ‘1
Merry #christmas and happy #newyear!
πŸŽ„8β˜ƒ2πŸ‘1
One more! This one is pricey 😁😁😁

#christmas #newyear #memory
β˜ƒ5πŸŽ„3πŸ‘2πŸŽ…1
This media is not supported in your browser
VIEW IN TELEGRAM
Instead of the year in review 😁

#apple #google #samsung #ai #calculator
😁5❀2πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
Merry #christmas and a happy #newyear, everyone!

Thank you for all your views, likes and shares! Wish you a clean code, bug-free solutions, fast builds and cheap hardware!

πŸŽ…β˜ƒοΈπŸŽ„
❀6πŸŽ„6πŸ‘1
🀣6πŸ‘1
❀4😁2πŸ‘1
🀣4πŸ‘3😁3
This media is not supported in your browser
VIEW IN TELEGRAM
Next-generation gamepad!

#weekendmeme #gaming
😁3πŸ™ˆ2❀1πŸ‘1
πŸ‘4😁2🀑1
😁4πŸ’―3πŸ‘1🀑1
Recently learned about a critical MongoDB vulnerability tracked as CVE-2025-14847 (aka MongoBleed) with a CVSS score of 8.7.

a flaw in MongoDB Server’s zlib-based network message decompression logic, which is processed prior to authentication. By sending malformed, compressed network packets, an unauthenticated attacker can trigger the server to mishandle decompressed message lengths, resulting in uninitialized heap memory being returned to the client. This allows attackers to remotely leak fragments of sensitive in-memory data without valid credentials or user interaction.


The fun part 😁:

At a code level, the vulnerability was caused by incorrect length handling in message_compressor_zlib.cpp. The affected logic returned the allocated buffer size (output.length()) instead of the actual decompressed data length, allowing undersized or malformed payloads to expose adjacent heap memory.


It is also worth noting that it affects instances with zlib compression enabled, which is the default configuration.

A bit more info at The Hacker News

#random_PoK #mongodb #InfoSec
πŸ‘3😁1🀯1
😁6πŸ‘3