Navigation
Recherche
|
Critical Unauthenticated RCE Flaw Impacts All GNU/Linux Systems
jeudi 26 septembre 2024, 04:00 , par Slashdot
'Looks like there's a storm brewing, and it's not good news,' writes ancient Slashdot reader jd. 'Whether or not the bugs are classically security defects or not, this is extremely bad PR for the Linux and Open Source community. It's not clear from the article whether this affects other Open Source projects, such as FreeBSD.' From a report: A critical unauthenticated Remote Code Execution (RCE) vulnerability has been discovered, impacting all GNU/Linux systems. As per agreements with developers, the flaw, which has existed for over a decade, will be fully disclosed in less than two weeks. Despite the severity of the issue, no Common Vulnerabilities and Exposures (CVE) identifiers have been assigned yet, although experts suggest there should be at least three to six. Leading Linux distributors such as Canonical and RedHat have confirmed the flaw's severity, rating it 9.9 out of 10. This indicates the potential for catastrophic damage if exploited. However, despite this acknowledgment, no working fix is still available. Developers remain embroiled in debates over whether some aspects of the vulnerability impact security.
Read more of this story at Slashdot.
https://it.slashdot.org/story/24/09/25/2150210/critical-unauthenticated-rce-flaw-impacts-all-gnulinu...
Voir aussi |
56 sources (32 en français)
Date Actuelle
ven. 15 nov. - 22:21 CET
|