• bigkahuna1986@lemmy.ml
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 months ago

    Unauthenticed RCE vs all GNU/Linux systems

    So this would probably be SSH related right? Otherwise what would all Linux systems have in common?

    • m-p{3}A
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      1
      ·
      2 months ago

      My bet is on Systemd.

    • CameronDev@programming.dev
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 months ago

      Not all Linux’s have SSH enabled, especially out of the box.

      They have some other posts about IPv6 parsing (also not universal), but that doesnt sound like an “easy” RCE.

    • schizo@forum.uncomfortable.business
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 months ago

      If it were SSH though, wouldn’t that ALSO include a wider blast radius than just Linux systems?

      Like OpenSSH is used all over the damn place, unless I guess there’s something specific about the issue that limits it to Linux hosts for some reason?

      • SpaceMan9000@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        He claims the blast radius is bigger, not just Linux. He also claims to be in talks with Apple. So the educated guess would still be openssh