udev4096 10 months ago

So far, the suggested hint is towards cups[0] which is a printing system for unix. I am not sure if it's even installed on all the distros by default

[0] - https://en.wikipedia.org/wiki/CUPS

  • imrejonk 10 months ago

    Care to share the source of this hint?

    • lambdadelirium 10 months ago

      I think it is from the speculation that this is due to a very common package that binds to all interfaces by default after installation

    • Berazu 10 months ago

      He forked the cups repo over a week ago.

  • ycombinatrix 10 months ago

    maybe i'm being overly pedantic but wouldn't that be a a CUPS specific RCE?

    the title claims "all" GNU/Linux systems are vulnerable

    • unluckier 10 months ago

      The thread that the title comes from is from a Twitter user that later stated about the issue: "And YES: I LOVE hyping the sh1t out of this stuff because apparently sensationalism is the only language that forces these people to fix. "

      As such, every single thing about the topic should be taken with a grain of salt. Starting with systems affected (it's not all GNU/Linux) and also CVSS score (I score it as a 6.3 instead of 9.9). Use your imagination to decide how much of what was posted is based on fact as opposed to fantasy.

imrejonk 10 months ago

I wonder if this "all GNU/Linux systems" is correct, or if we'll see some nuance added in a couple of hours/days. I'd be a monstrous patch day if this RCE really impacts all GNU/Linux systems.