Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago
1–10 of 10 posts
Re: Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago
#2* Full disclosure happening in less than 2 weeks (as agreed with devs).
* Still no working fix.
Re: Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago
#3Re: Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago
#4* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago. * Full disclosure happening in less than 2 weeks (as agreed with devs). * Still no working fix.
Re: Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago
#5Re: Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago
#6So I understand this means we will need to wait till October 6 for more details. Would it be safe to assume anything being talked about right now is speculation?
Re: Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago
#7Re: Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago
#8Re: Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago
#9Re: Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago
#10It's probably something that's unexploitable in practice or rarely enabled by default or both if the developers aren't too bothered about fixing it. Sounds like yet another vulnerability that's more hype than anything serious.
But the "(+ others)" seems to imply it's not Linux kernel.
And OpenSSH is maintained by OpenBSD folks, who take security extremely seriously. I cannot imagine them taking 3+ weeks and not having security fix, nor arguing whether "Unauthenticated RCE" has a security impact.
So I am guessing it's one of the other common packages, probably not installed on every computer and/or not normally exposed to the internet.