lurklurk@lemmy.worldtoLinux@programming.dev•'Critical' vulnerability in OpenSSH uncovered, affects almost all Linux systems
01·
6 months agothe in depth technical details
TL;DR; sigalarm handler calls syslog which isn’t safe to call from a signal handler context.
Their example exploit needed about 10k attempts to get a remote shell so it’s not fast or quiet, but a neat find regardless
People should find a better foundation for self-esteem than hating linux distros. They’re mostly ok, and without debian Linux wouldn’t be what it is today
Preferring a certain distro is fine but why care if others like something else?