Another long term dangerous flaw?

Discussion in 'Random Nonsense' started by cloasters, Oct 22, 2016.

  1. cloasters

    cloasters Moderator

    Joined:
    Jul 3, 2013
    Messages:
    8,383
    Likes Received:
    82
    Trophy Points:
    48
  2. Daerandin

    Daerandin Well-Known Member

    Joined:
    Oct 18, 2013
    Messages:
    1,157
    Likes Received:
    258
    Trophy Points:
    83
    Location:
    Northern Norway
    Home page:
    This should not pose any problem for personal home use. Someone either requires local access to a computer to exploit this, or the computer must run some kind of server that allows remote shell access or file uploads. Or possibly a web server that is not properly secured against sql injection attacks.

    Even servers that allow file uploads would still need to execute uploaded files in order for the exploit to be an issue.

    So all home users need not worry, and I expect patched kernels are becoming available in most distributions shortly.

    What is troubling is that it has existed for so long, which means there are probably several compromised servers in the world. And once a server has been compromised, it can be difficult to confidently secure it again without doing a full reinstall.
  3. cloasters

    cloasters Moderator

    Joined:
    Jul 3, 2013
    Messages:
    8,383
    Likes Received:
    82
    Trophy Points:
    48
    Great news, thank you Daerandin! Yes, nine years is a mighty long time without a remedy or patch.
  4. Daniel~

    Daniel~ Chief BBS Administrator Staff Member

    Joined:
    Dec 17, 2012
    Messages:
    11,352
    Likes Received:
    169
    Trophy Points:
    63
    Location:
    Greenwater WA
    Home page:
    George why live in such a dangerous world? Gandhi found peace here, Martian found peace here...we can find peace here. Hacking our Linux boxes remains more trouble than it's worth to any one except your wifes boyfriend.":O}.
  5. Gizmo

    Gizmo Chief Site Administrator Staff Member

    Joined:
    Dec 6, 2012
    Messages:
    2,282
    Likes Received:
    172
    Trophy Points:
    63
    Location:
    Webb City, Missouri
    Home page:
    Any local privilege escalation can be turned into a remote one by simply finding a web application that can be compromised, or a SQL injection vulnerability.

    And saying that the bug has been unpatched for nine years is misleading. That the bug has EXISTED for nine years is indisputable, but in all that time it's also been UNIDENTIFIED. Now that it has been identified, it's being fixed.
    booman likes this.
  6. cloasters

    cloasters Moderator

    Joined:
    Jul 3, 2013
    Messages:
    8,383
    Likes Received:
    82
    Trophy Points:
    48
    Now this is good news, thanks Gizmo! Linux is the best, who would want to argue with that?

Share This Page