Language Selection

English French German Italian Portuguese Spanish

Critical Linux vulnerability imperils users, even after “silent” fix

Filed under
Linux
Security

For years, the Linux operating system has contained a high-severity vulnerability that gives untrusted users with restricted accounts nearly unfettered "root" access over machines, including servers running in shared Web hosting facilities and other sensitive environments. Surprisingly, most users remain wide open even now, more than a month after maintainers of the open-source OS quietly released an update that patched the gaping hole.

The severity of the bug, which resides in the Linux kernel's "perf," or performance counters subsystem, didn't become clear until Tuesday, when attack code exploiting the vulnerability became publicly available (note: some content on this site is not considered appropriate in many work environments). The new script can be used to take control of servers operated by many shared Web hosting providers, where dozens or hundreds of people have unprivileged accounts on the same machine.

rest here




More in Tux Machines

Android Leftovers

today's howtos

Mozilla News

  • WebExtensions in Firefox 48
  • Mozilla's WebExtensions API Is In Good Shape For Firefox 48
    Mozilla has announced that for Firefox 48 their WebExtensions API is considered to be in a stable state. They encourage developers looking to develop browser add-ons to begin using this new API. WebExtensions is an API for implementing new browser add-ons/extensions that makes it easier to port to/from other browsers, is compatible with Firefox's Electroloysis, and should be easier to work with than the current APIs. In particular, Google designed portions of the WebExtensions API around Google's Blink extension API.
  • Mozilla a Step Closer to Thunderbird Decision
    The good news is that the folks at Mozilla seem to be determined to find Thunderbird a good home where it will be able to grow and find newfound success. This isn’t surprising. As Surman pointed out in his post, the project is quite popular among those associated with the foundation — but that popularity is also contributing to the problem Mozilla has with keeping the project in-house.