Random insights of our daily work
After a two years long break the Summit on a Summit was back in early June this year.
Simple questions often have not so simple answers. One example is the question is, what priority does this process have?
Squashfs-tools recently fixed a security issue. In this blog post we show how to re-exploit it and how it got mitigated
ALPSS was back in 2021 and here's what happened :-)
If Startups invest money into security right from the scratch, the costs will be much lower in the end. Why? Read this article!
The upcoming Yocto 3.4 release will contain a small contribution by us. Over the last two years we learned to love EROFS, so we decided to add support for it to Yocto.
Imagine you find yourself in a restricted environment and you need some Linux rootfs that runs on the embedded system you just managed get access to. Of course the CPU architecture of the embedded system is not the same as your workstation. The circumstances are further complicated by the fact that the userspace should offer enough tooling to build a C/C++ application. In such a situation docker can help, but in an unexpected way.
In this blog post we will take a closer look at a symlink race vulnerability from 2018 in docker. We think the vulnerability is quite interesting since it is easy to exploit but not so obvious to find while reviewing. Attentive readers may ask themselves whether they’d have noticed the issue while developing or reviewing the affected lines of code.
Presenting what sigma star is doing and who is the team of sigma star.
+43 5 9980 400 00
sigma star gmbh
Eduard-Bodem-Gasse 6, 1st floor
6020 Innsbruck | Austria