lemmy.963.pm
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Alphane Moon@lemmy.world to Opensource@programming.devEnglish · 17 days ago

New 7-Zip high-severity vulnerabilities expose systems to remote attackers — users should update to version 25 ASAP

www.tomshardware.com

external-link
message-square
16
link
fedilink
164
external-link

New 7-Zip high-severity vulnerabilities expose systems to remote attackers — users should update to version 25 ASAP

www.tomshardware.com

Alphane Moon@lemmy.world to Opensource@programming.devEnglish · 17 days ago
message-square
16
link
fedilink
Patches for two high-severity ZIP parsing flaws have quietly been available since July.
  • tordenflesk@lemmy.world
    link
    fedilink
    arrow-up
    32
    ·
    16 days ago

    There is literally no update functionality baked in

    Good, that’s what package managers are for.

    • JustEnoughDucks@feddit.nl
      link
      fedilink
      arrow-up
      20
      ·
      16 days ago

      If only windows had package managers for the 100 million machines with 7zip out there

      • The_Decryptor@aussie.zone
        link
        fedilink
        English
        arrow-up
        13
        ·
        16 days ago

        winget is actually smart enough to manage stuff installed outside of it, but that still requires users to actually use winget to begin with.

      • tordenflesk@lemmy.world
        link
        fedilink
        arrow-up
        8
        ·
        16 days ago

        Winget, Chocolatey, Scoop, VU, Cargo. I could go on…

        • JustEnoughDucks@feddit.nl
          link
          fedilink
          arrow-up
          2
          ·
          16 days ago

          Can’t you not use those unless you have admin rights on your PC which the vast majority of corporations (rightly) don’t give.

          • tordenflesk@lemmy.world
            link
            fedilink
            arrow-up
            6
            ·
            16 days ago

            Right, it’s the end-users responsibility to update software in a corporate environment is it?

            Scoop, by default deploys in ~\Scoop, and works in 95% of cases with a regular user.

          • monk@lemmy.unboiled.info
            link
            fedilink
            arrow-up
            3
            ·
            16 days ago

            Then the corporations are the ones on the hook to to update it. shrug

      • circuscritic@lemmy.ca
        link
        fedilink
        arrow-up
        3
        ·
        16 days ago

        Winget exists, but I believe it has to be manually setup, and manually used.

        It’s been a while since I used Windows in general, so my knowledge is a bit outdated/rusty.

        • AtariDump@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          16 days ago

          Manually triggered, yes. Manually setup, no - it’s already a part of Winblows 11.

      • bizarroland@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        16 days ago

        I like https://ruckzuck.tools/

        It has a section for updating and then a section for exploring for new programs that’s relatively sanely sorted.

Opensource@programming.dev

opensource@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !opensource@programming.dev

A community for discussion about open source software! Ask questions, share knowledge, share news, or post interesting stuff related to it!

Credits

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

⠀


Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 985 users / day
  • 590 users / week
  • 1.3K users / month
  • 1.32K users / 6 months
  • 1 local subscriber
  • 4.19K subscribers
  • 154 Posts
  • 411 Comments
  • Modlog
  • mods:
  • Pierre-Yves Lapersonne@programming.dev
  • BE: 0.19.13
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org