On September 27, a serious remote code execution (RCE) vulnerability was exposed in the Linux circle. It has existed for more than 10 years and affects almost all GNU/Linux distributions. There is currently no patch to fix it, but it can be mitigated.
Software developer Simone Margaritelli first disclosed these RCE vulnerabilities in a tweet on the X platform on September 23. The relevant development teams have been notified and will be fully disclosed in the next two weeks.
Vulnerability damage
Margaritelli said that these vulnerabilities do not currently have CVE tracking numbers assigned, but there will be at least 3, and ideally 6.
Canonical (Ubuntu developer), Red Hat, and other distribution development teams and companies have confirmed the severity of these RCE vulnerabilities, with an estimated CVSS score of 9.9 (out of 10, with higher scores representing more dangerous), which indicates that if exploited, it could cause catastrophic damage.
Vulnerability Details
The vulnerability mainly exists in the Unix printing system CUPS. If the user is running CUPS and has enabled cups-browsed, there is a risk of being attacked, causing the user's device to be remotely hijacked.
However, the CUPS development team was divided on how to deal with the vulnerability, with some members arguing about the security impact of the vulnerability on actual operations, which Margaritelli expressed frustration with.
The researchers note that despite providing multiple proofs of concepts (PoCs) that systematically disproven developers’ assumptions, progress remains slow.
Mitigation
IT Home quoted Margaritelli as saying that there is currently no patch, and users can try the following mitigation solutions:
-
Disable or remove cups-browsed service
-
Update your CUPS installation to pull in security updates as they become available.
-
Block access to UDP port 631 and consider turning off DNS-SD.
-
If port 631 is not directly accessible, an attacker may be able to exploit it by spoofing zeroconf, mDNS, or DNS-SD advertisements.
Previous article:The agenda of the 6th China Embedded Operating System Technology and Industry Development Forum was released
Next article:China Academy of Information and Communications Technology, Beijing University of Posts and Telecommunications and Tsinghua University jointly released an open source "tangible" embodied intelligent operating system
Recommended ReadingLatest update time:2024-11-21 20:13
- Popular Resources
- Popular amplifiers
- Why is the vehicle operating system (Vehicle OS) becoming more and more important?
- Car Sensors - A detailed explanation of LiDAR
- Simple differences between automotive (ultrasonic, millimeter wave, laser) radars
- Comprehensive knowledge about automobile circuits
- Introduction of domestic automotive-grade bipolar latch Hall chip CHA44X
- Infineon Technologies and Magneti Marelli to Drive Regional Control Unit Innovation with AURIX™ TC4x MCU Family
- Power of E-band millimeter-wave radar
- Hardware design of power supply system for automobile controller
- Driving Automation Safety and Economic Engineering
Professor at Beihang University, dedicated to promoting microcontrollers and embedded systems for over 20 years.
- Intel promotes AI with multi-dimensional efforts in technology, application, and ecology
- ChinaJoy Qualcomm Snapdragon Theme Pavilion takes you to experience the new changes in digital entertainment in the 5G era
- Infineon's latest generation IGBT technology platform enables precise control of speed and position
- Two test methods for LED lighting life
- Don't Let Lightning Induced Surges Scare You
- Application of brushless motor controller ML4425/4426
- Easy identification of LED power supply quality
- World's first integrated photovoltaic solar system completed in Israel
- Sliding window mean filter for avr microcontroller AD conversion
- What does call mean in the detailed explanation of ABB robot programming instructions?
- Breaking through the intelligent competition, Changan Automobile opens the "God's perspective"
- The world's first fully digital chassis, looking forward to the debut of the U7 PHEV and EV versions
- Design of automotive LIN communication simulator based on Renesas MCU
- When will solid-state batteries become popular?
- Adding solid-state batteries, CATL wants to continue to be the "King of Ning"
- The agency predicts that my country's public electric vehicle charging piles will reach 3.6 million this year, accounting for nearly 70% of the world
- U.S. senators urge NHTSA to issue new vehicle safety rules
- Giants step up investment, accelerating the application of solid-state batteries
- Guangzhou Auto Show: End-to-end competition accelerates, autonomous driving fully impacts luxury...
- Lotus launches ultra-900V hybrid technology "Luyao" to accelerate the "Win26" plan
- A new micropython discussion group has been created on the forum. Welcome everyone interested to join
- [RVB2601 Creative Application Development] Network Weather Clock
- The process of responding to interrupts in DSP
- [RVB2601 Creative Application Development] 1. Development Environment Construction
- EEWORLD University ---- Live Replay: Microchip Security Series 6 - Trust Your Firmware: Secure Boot Application Processors
- [Home Smart Lighting Control and Indoor Environment Monitoring System]--8. Merge 2 projects in ON-SEMI development software
- ADI launches new high-speed and high-precision instrumentation amplifier
- 51 MCU sends data to the serial port
- How many of these difficult questions related to high-speed PCBs can you answer correctly?
- How to generate three-phase SPWM waveform