GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    elacheche@mastodon.tn's status on Friday, 27-Sep-2024 05:08:12 JST elacheche elacheche

    Unauthenticated #RCE vs all #GNU / #Linux systems (plus others) disclosed 3 weeks ago.
    #Canonical, #RedHat and others have confirmed the severity, a 9.9/10 😱😱😱😱😱
    https://threadreaderapp.com/thread/1838169889330135132.html

    In conversation about 9 months ago from mastodon.tn permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: shots.threadreader.app
      Thread by @evilsocket on Thread Reader App
      from @evilsocket
      @evilsocket: * Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago. * Full disclosure happening in less than 2 weeks (as agreed with devs). * Still no CVE assigned (there should be at...…
    • Embed this notice
      not Evander Sinque (filis@mastodon.social)'s status on Friday, 27-Sep-2024 05:08:10 JST not Evander Sinque not Evander Sinque
      in reply to

      @elacheche it's #CUPS

      In conversation about 9 months ago permalink
    • Embed this notice
      feld (feld@friedcheese.us)'s status on Friday, 27-Sep-2024 05:08:10 JST feld feld
      in reply to
      • not Evander Sinque
      @FiLiS @elacheche "plus others" but won't give any details? I'm super skeptical tbh

      prove one distro vendor confirmed this that isn't shipping glibc please
      In conversation about 9 months ago permalink
    • Embed this notice
      elacheche@mastodon.tn's status on Friday, 27-Sep-2024 05:55:09 JST elacheche elacheche
      in reply to
      • not Evander Sinque
      • feld

      @feld @FiLiS

      I agree, he made it look like something "built-in" or business/user critical..

      The CVE can have a high score, but it's impact is not big.. And most of the "default" cups installations (aka end users) are not reachable via the net..

      In conversation about 9 months ago permalink
      feld likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.