4 ms·
> you regularly see downright absurd stuff like this That's a bug which only occurs on five year old distributions and which was fixed years before any exploit
by zik 7y ago
> you regularly see downright absurd stuff like this
That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found. Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.
- RaleyField 7y agols -l ~/.bashrc and by design.
- starfallg 7y agoYeah. The first article he linked to specifically called out Windows for doing fonts in kernel-space, to put that gstreamer vulnerability in context.
- zaarn 7y agoAn attacker can trivial phish to sudo password and execute arbitrary commands every time you open the terminal. shellrc and profile as well as almost all core unix tools allow running arbitrary code. You can even bend the paths of bashrc and friends so the user can't trivially inspect them without dropping to root first (at which point, arbitrary code can trivially obtain root access too)
- FDSGSG 7y ago> That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found I don't think we're reading the same post unless you got confused by the part where he discusses the exploit not the bug. > Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems. Compared to what? FreeBSD? Certainly not any modern desktop OS. MSFT is investing heavily in exploit mitigations while Linux distros are probably still struggling with ASLR. https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf https://www.blackhat.com/docs/us-16/materials/us-16-Weston-W...