The RCE that AMD won't fix

90 points by achivetta


lina

Physical access and account compromise are one thing, but considering man in the middle out of scope sure is a choice... anyone can do that on any public WiFi.

enpo

This seems like an easy thing to fix. They already request the manifest over HTTPS and the individual files are on the same domain, so TLS are already in place. The fix is literally to replace 'http' with 'https' in the template they use to generate the manifest. If I were the recipient of the report, it would have been easier for me to fix it than to find an exception in the legalese.

adrien

The flaw is potentially very similar to https://notepad-plus-plus.org/news/hijacked-incident-info-update/ .

What I can't tell in the case of the AMD driver is whether there is a cryptographic checksum somewhere because only a part of the XML file is shown. It's also possible there is a verification at a later stage. Unfortunately the author doesn't say anything about these: neither their presence, nor their absence.