PSA: Update your GNU/Linux systems, NOW!
Trådens avsändare: Mr. Satan (X)
Mr. Satan (X)
Mr. Satan (X)
Engelska till Indonesiska
Oct 5, 2023

Qualys said its team successfully identified and exploited the vulnerability to allow a local attacker to achieve root privileges on the default installations of Fedora 37 and 38, Ubuntu 22.04 and 23.04, and Debian 12 and 13. Most other distributions are said to be affected, though Alpine Linux is not because it uses musl libc rather than glibc.

[…]

Red Hat has assigned the issue as CVE-2023-4911, and given it a CVSS score of 7.8 out of 10 in terms of severity.


https://www.theregister.com/2023/10/04/linux_looney_tunables_bug/

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.


https://access.redhat.com/security/cve/cve-2023-4911

Personal remark:
At least this is not a remote code execution vulnerability. The attacker needs local access to your system to pull it off. Having said that, I've installed the updates this morning as soon as I read the news. Better safe than sorry.

[Edited at 2023-10-05 00:56 GMT]


Jean Dimitriadis
 


To report site rules violations or get help, contact a site moderator:

Moderatorer för detta forum
Prachya Mruetusatorn[Call to this topic]

You can also contact site staff by submitting a support request »

PSA: Update your GNU/Linux systems, NOW!






TM-Town
Manage your TMs and Terms ... and boost your translation business

Are you ready for something fresh in the industry? TM-Town is a unique new site for you -- the freelance translator -- to store, manage and share translation memories (TMs) and glossaries...and potentially meet new clients on the basis of your prior work.

More info »
LinguaCore
AI Translation at Your Fingertips

The underlying LLM technology of LinguaCore offers AI translations of unprecedented quality. Quick and simple. Add a human linguistic review at the end for expert-level quality at a fraction of the cost and time.

More info »