PSA: Update your GNU/Linux systems, NOW!
Thread poster: Mr. Satan (X)
Mr. Satan (X)
Mr. Satan (X)
English to Indonesian
Oct 5, 2023

Qualys said its team successfully identified and exploited the vulnerability to allow a local attacker to achieve root privileges on the default installations of Fedora 37 and 38, Ubuntu 22.04 and 23.04, and Debian 12 and 13. Most other distributions are said to be affected, though Alpine Linux is not because it uses musl libc rather than glibc.

[…]

Red Hat has assigned the issue as CVE-2023-4911, and given it a CVSS score of 7.8 out of 10 in terms of severity.


https://www.theregister.com/2023/10/04/linux_looney_tunables_bug/

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.


https://access.redhat.com/security/cve/cve-2023-4911

Personal remark:
At least this is not a remote code execution vulnerability. The attacker needs local access to your system to pull it off. Having said that, I've installed the updates this morning as soon as I read the news. Better safe than sorry.

[Edited at 2023-10-05 00:56 GMT]


Jean Dimitriadis
 


To report site rules violations or get help, contact a site moderator:

Moderator(s) of this forum
Prachya Mruetusatorn[Call to this topic]

You can also contact site staff by submitting a support request »

PSA: Update your GNU/Linux systems, NOW!






CafeTran Espresso
You've never met a CAT tool this clever!

Translate faster & easier, using a sophisticated CAT tool built by a translator / developer. Accept jobs from clients who use Trados, MemoQ, Wordfast & major CAT tools. Download and start using CafeTran Espresso -- for free

Buy now! »
Protemos translation business management system
Create your account in minutes, and start working! 3-month trial for agencies, and free for freelancers!

The system lets you keep client/vendor database, with contacts and rates, manage projects and assign jobs to vendors, issue invoices, track payments, store and manage project files, generate business reports on turnover profit per client/manager etc.

More info »