Re: [R-pkg-devel] New libcurl coming / question for pkg authors

2016-10-23 Thread Jeroen Ooms
Thanks for the heads-up. What are the type of attacks that you expect R users might be affected by? Most problems discussed on the libcurl mailing lists are local vulnerabilities. E.g. an out-of-bounds read or buffer overflow exploit doesn't do anything that can easily be done from R itself? I gu

[R-pkg-devel] New libcurl coming / question for pkg authors

2016-10-21 Thread Bob Rudis
(didn't know where else to post this, but pkg authors seemed to be a good group to run this by) Some folks may know I work in cybersecurity and my org's been talking with the curl/libcurl community regarding: https://curl.haxx.se/mail/lib-2016-10/0076.html TLDR: there's a new libcurl/curl coming