D•Scribe
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
schnurrito@discuss.tchncs.de to Linux@programming.dev · 1 month ago

Bugs Found in sudo

www.linux-magazine.com

external-link
message-square
8
link
fedilink
  • cross-posted to:
  • linux@lemmy.world
39
external-link

Bugs Found in sudo

www.linux-magazine.com

schnurrito@discuss.tchncs.de to Linux@programming.dev · 1 month ago
message-square
8
link
fedilink
  • cross-posted to:
  • linux@lemmy.world
Bugs Found in sudo » Linux Magazine
www.linux-magazine.com
external-link
Two critical flaws allow users to gain access to root privileges.
alert-triangle
You must log in or # to comment.
  • elmicha@feddit.org
    link
    fedilink
    arrow-up
    26
    ·
    1 month ago

    In case anyone wonders: these are the same bugs reported (and fixed) last week, not new ones.

  • a_person@lemmy.world
    link
    fedilink
    arrow-up
    11
    arrow-down
    1
    ·
    edit-2
    1 month ago

    Damn, a cvss score of 9.3 is wild

  • syd@lemy.lol
    link
    fedilink
    arrow-up
    7
    arrow-down
    3
    ·
    1 month ago

    So ‘sudo-rs’ guys were right?

    • 0x0@lemmy.zip
      link
      fedilink
      arrow-up
      22
      ·
      edit-2
      1 month ago

      The vulnerability in question would’ve still happened if written in rust, it was not a memory leak.
      More an instance of feature creep, as the solution was to remove the functionality.

      • Comexs@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        Would something like ‘doas’ have the same issue?

        • 0x0@lemmy.zip
          link
          fedilink
          arrow-up
          1
          ·
          1 month ago

          I don’t believe so and it has been suggested as an alternative.

    • e8d79@discuss.tchncs.de
      link
      fedilink
      arrow-up
      5
      arrow-down
      1
      ·
      1 month ago

      I would rather go with a completely new approach like the one of run0.

    • macniel@feddit.org
      link
      fedilink
      arrow-up
      2
      ·
      1 month ago

      Rusty Bois are never right!

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca
  • Matrix instant messaging group chat

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 641 users / day
  • 1.79K users / week
  • 3.97K users / month
  • 9.89K users / 6 months
  • 6 local subscribers
  • 8.85K subscribers
  • 1.85K Posts
  • 11.8K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • UI: unknown version
  • BE: 0.19.12
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org