Brdsnest Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Blaze (he/him)@lemmy.zip to Linux@programming.dev · 1 year ago

'Critical' vulnerability in OpenSSH uncovered, affects almost all Linux systems

www.computing.co.uk

external-link
message-square
6
fedilink
1
external-link

'Critical' vulnerability in OpenSSH uncovered, affects almost all Linux systems

www.computing.co.uk

Blaze (he/him)@lemmy.zip to Linux@programming.dev · 1 year ago
message-square
6
fedilink
Researchers at the Qualys Threat Research Unit (TRU) have unearthed discovered a critical security flaw in OpenSSH's server (sshd) in glibc-based Linux systems.
alert-triangle
You must log in or register to comment.
  • Lung@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    1 year ago

    It’s shit like this that makes me convinced that governments can easily hack into pretty much every system

    • unexposedhazard@discuss.tchncs.de
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      Well only if they know about it before it gets patched…

      • scrion@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        That’s why there is a huge market for 0-day exploits.

  • lurklurk@lemmy.world
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    1 year ago

    the in depth technical details

    TL;DR; sigalarm handler calls syslog which isn’t safe to call from a signal handler context.

    Their example exploit needed about 10k attempts to get a remote shell so it’s not fast or quiet, but a neat find regardless

  • OsrsNeedsF2P@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    1 year ago

    They have named this vulnerability “regreSSHion”, since it represents the re-emergence of a bug that was previously patched in 2006

    That’s a great name

    • runeko@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      Agreed, but I had to disable autocorrect to type it on my phone.

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca
  • Matrix instant messaging group chat

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 336 users / day
  • 1.58K users / week
  • 4.39K users / month
  • 9.29K users / 6 months
  • 1 local subscriber
  • 8.39K subscribers
  • 1.85K Posts
  • 13.1K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org