PSA: Update your GNU/Linux systems, NOW!
Tópico cartaz: Mr. Satan (X)
Mr. Satan (X)
Mr. Satan (X)
inglês para indonésio
Oct 5, 2023

Qualys said its team successfully identified and exploited the vulnerability to allow a local attacker to achieve root privileges on the default installations of Fedora 37 and 38, Ubuntu 22.04 and 23.04, and Debian 12 and 13. Most other distributions are said to be affected, though Alpine Linux is not because it uses musl libc rather than glibc.

[…]

Red Hat has assigned the issue as CVE-2023-4911, and given it a CVSS score of 7.8 out of 10 in terms of severity.


https://www.theregister.com/2023/10/04/linux_looney_tunables_bug/

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.


https://access.redhat.com/security/cve/cve-2023-4911

Personal remark:
At least this is not a remote code execution vulnerability. The attacker needs local access to your system to pull it off. Having said that, I've installed the updates this morning as soon as I read the news. Better safe than sorry.

[Edited at 2023-10-05 00:56 GMT]


Jean Dimitriadis
 


To report site rules violations or get help, contact a site moderator:

Moderador(es) deste fórum
Prachya Mruetusatorn[Call to this topic]

You can also contact site staff by submitting a support request »

PSA: Update your GNU/Linux systems, NOW!






CafeTran Espresso
You've never met a CAT tool this clever!

Translate faster & easier, using a sophisticated CAT tool built by a translator / developer. Accept jobs from clients who use Trados, MemoQ, Wordfast & major CAT tools. Download and start using CafeTran Espresso -- for free

Buy now! »
Anycount & Translation Office 3000
Translation Office 3000

Translation Office 3000 is an advanced accounting tool for freelance translators and small agencies. TO3000 easily and seamlessly integrates with the business life of professional freelance translators.

More info »