Pricefield | Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Blaze (he/him) to [email protected] • 1 year ago

'Critical' vulnerability in OpenSSH uncovered, affects almost all Linux systems

www.computing.co.uk

external-link
message-square
39
fedilink
  • cross-posted to:
  • [email protected]
243
external-link

'Critical' vulnerability in OpenSSH uncovered, affects almost all Linux systems

www.computing.co.uk

Blaze (he/him) to [email protected] • 1 year ago
message-square
39
fedilink
  • cross-posted to:
  • [email protected]
Researchers at the Qualys Threat Research Unit (TRU) have unearthed discovered a critical security flaw in OpenSSH's server (sshd) in glibc-based Linux systems.
  • @[email protected]
    link
    fedilink
    10•1 year ago

    That’s why there is a huge market for 0-day exploits.

    • @[email protected]
      link
      fedilink
      3•1 year ago

      Isn’t there attempts to sneak in vulnerabilities with new commits?

      • @[email protected]
        link
        fedilink
        6•
        edit-2
        1 year ago

        Yes, targeted attacks like that definitely exist, most famously maybe the most recent social pressure to merge a vulnerability to the xz library by actor “Jia Tan”:

        https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/

        This started a whole discussion about relying on (often unpaid) volunteer work for critical systems and the pressure and negativity these people face, which is a discussion that was absolutely needed, and which we are still lightyears away from fixing.

        Currently, open source is still treated like this: https://trac.ffmpeg.org/ticket/10341

        (I can only recommend reading the whole story around this issue, which boils down to Microsoft admitting they rely on an open source project for something they consider critical to their customers, but not willing to pay the maintainer a bounty for fixing the issue)

[email protected]

[email protected]
Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A community for everything relating to the GNU/Linux operating system

Also check out:

  • [email protected]
  • [email protected]

Original icon base courtesy of [email protected] and The GIMP

  • 108 users / day
  • 441 users / week
  • 849 users / month
  • 2.1K users / 6 months
  • 2 subscribers
  • 1.92K Posts
  • 14.6K Comments
  • Modlog
  • mods:
  • Ategon
  • adr1an
  • dwraf_of_ignorance
  • UI: 0.18.4
  • BE: 0.18.2
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org