Treasure@feddit.org to Cybersecurity@sh.itjust.worksEnglish · edit-21 month agoUnauthenticated RCE vs all GNU/Linux systems to be fully disclosed in 2 weeks with no working fix yetnitter.poast.orgexternal-linkmessage-square16fedilinkarrow-up11arrow-down10file-textcross-posted to: linux@lemmy.ml
arrow-up11arrow-down1external-linkUnauthenticated RCE vs all GNU/Linux systems to be fully disclosed in 2 weeks with no working fix yetnitter.poast.orgTreasure@feddit.org to Cybersecurity@sh.itjust.worksEnglish · edit-21 month agomessage-square16fedilinkfile-textcross-posted to: linux@lemmy.ml
minus-squarebigkahuna1986@lemmy.mllinkfedilinkEnglisharrow-up0·1 month ago Unauthenticed RCE vs all GNU/Linux systems So this would probably be SSH related right? Otherwise what would all Linux systems have in common?
minus-squareCameronDev@programming.devlinkfedilinkEnglisharrow-up0·1 month agoNot all Linux’s have SSH enabled, especially out of the box. They have some other posts about IPv6 parsing (also not universal), but that doesnt sound like an “easy” RCE.
minus-squareschizo@forum.uncomfortable.businesslinkfedilinkEnglisharrow-up0·1 month agoIf it were SSH though, wouldn’t that ALSO include a wider blast radius than just Linux systems? Like OpenSSH is used all over the damn place, unless I guess there’s something specific about the issue that limits it to Linux hosts for some reason?
minus-squareSpaceMan9000@lemmy.worldlinkfedilinkEnglisharrow-up0·1 month agoHe claims the blast radius is bigger, not just Linux. He also claims to be in talks with Apple. So the educated guess would still be openssh
minus-squarethesmokingman@programming.devlinkfedilinkEnglisharrow-up0·1 month agoThat’s not all GNU/Linux though. Either the OP doesn’t understand a very common container OS, Alpine, doesn’t use systemd (also Void Linux and others outside the container space) or it’s something else.
minus-squareburgersc12@mander.xyzlinkfedilinkEnglisharrow-up0·1 month agoHow would this be unsurprising? Is systemd known for this kind of thing or something?
So this would probably be SSH related right? Otherwise what would all Linux systems have in common?
Not all Linux’s have SSH enabled, especially out of the box.
They have some other posts about IPv6 parsing (also not universal), but that doesnt sound like an “easy” RCE.
If it were SSH though, wouldn’t that ALSO include a wider blast radius than just Linux systems?
Like OpenSSH is used all over the damn place, unless I guess there’s something specific about the issue that limits it to Linux hosts for some reason?
He claims the blast radius is bigger, not just Linux. He also claims to be in talks with Apple. So the educated guess would still be openssh
My bet is on Systemd.
That’s not all GNU/Linux though. Either the OP doesn’t understand a very common container OS, Alpine, doesn’t use systemd (also Void Linux and others outside the container space) or it’s something else.
Oh that would be baaaad
And unsurprising
How would this be unsurprising? Is systemd known for this kind of thing or something?
https://pwnies.com/systemd-bugs/