Brdsnest Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Blaze (he/him)@lemmy.zip to Linux@programming.dev · 2 years ago

'Critical' vulnerability in OpenSSH uncovered, affects almost all Linux systems

www.computing.co.uk

external-link
message-square
6
fedilink
1
external-link

'Critical' vulnerability in OpenSSH uncovered, affects almost all Linux systems

www.computing.co.uk

Blaze (he/him)@lemmy.zip to Linux@programming.dev · 2 years ago
message-square
6
fedilink
Researchers at the Qualys Threat Research Unit (TRU) have unearthed discovered a critical security flaw in OpenSSH's server (sshd) in glibc-based Linux systems.
alert-triangle
You must log in or register to comment.
  • Lung@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    2 years ago

    It’s shit like this that makes me convinced that governments can easily hack into pretty much every system

    • unexposedhazard@discuss.tchncs.de
      link
      fedilink
      arrow-up
      0
      ·
      2 years ago

      Well only if they know about it before it gets patched…

      • scrion@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        2 years ago

        That’s why there is a huge market for 0-day exploits.

  • lurklurk@lemmy.world
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    2 years ago

    the in depth technical details

    TL;DR; sigalarm handler calls syslog which isn’t safe to call from a signal handler context.

    Their example exploit needed about 10k attempts to get a remote shell so it’s not fast or quiet, but a neat find regardless

  • OsrsNeedsF2P@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    2 years ago

    They have named this vulnerability “regreSSHion”, since it represents the re-emergence of a bug that was previously patched in 2006

    That’s a great name

    • runeko@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      2 years ago

      Agreed, but I had to disable autocorrect to type it on my phone.

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca
  • our Matrix group chat
  • !reactos@programming.dev

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 450 users / day
  • 2.57K users / week
  • 4.49K users / month
  • 10.9K users / 6 months
  • 1 local subscriber
  • 13K subscribers
  • 4.06K Posts
  • 32.2K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org