Aggregatet
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Blaze (he/him)@lemmy.zip to Linux@programming.dev · 1 year ago

'Critical' vulnerability in OpenSSH uncovered, affects almost all Linux systems

www.computing.co.uk

external-link
message-square
39
fedilink
245
external-link

'Critical' vulnerability in OpenSSH uncovered, affects almost all Linux systems

www.computing.co.uk

Blaze (he/him)@lemmy.zip to Linux@programming.dev · 1 year ago
message-square
39
fedilink
Researchers at the Qualys Threat Research Unit (TRU) have unearthed discovered a critical security flaw in OpenSSH's server (sshd) in glibc-based Linux systems.
  • unexposedhazard@discuss.tchncs.de
    link
    fedilink
    arrow-up
    5
    ·
    1 year ago

    Well only if they know about it before it gets patched…

    • scrion@lemmy.world
      link
      fedilink
      arrow-up
      10
      ·
      1 year ago

      That’s why there is a huge market for 0-day exploits.

      • vxx@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        1 year ago

        Isn’t there attempts to sneak in vulnerabilities with new commits?

        • scrion@lemmy.world
          link
          fedilink
          arrow-up
          6
          ·
          edit-2
          1 year ago

          Yes, targeted attacks like that definitely exist, most famously maybe the most recent social pressure to merge a vulnerability to the xz library by actor “Jia Tan”:

          https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/

          This started a whole discussion about relying on (often unpaid) volunteer work for critical systems and the pressure and negativity these people face, which is a discussion that was absolutely needed, and which we are still lightyears away from fixing.

          Currently, open source is still treated like this: https://trac.ffmpeg.org/ticket/10341

          (I can only recommend reading the whole story around this issue, which boils down to Microsoft admitting they rely on an open source project for something they consider critical to their customers, but not willing to pay the maintainer a bounty for fixing the issue)

    • teawrecks@sopuli.xyz
      link
      fedilink
      arrow-up
      6
      ·
      1 year ago

      The NSA is doubtless sitting on a trove of these types of vulnerabilities to use when they really need access to something.

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca
  • Matrix instant messaging group chat

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 286 users / day
  • 1.54K users / week
  • 4.31K users / month
  • 9.42K users / 6 months
  • 2 local subscribers
  • 8.39K subscribers
  • 1.91K Posts
  • 13.7K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org