this post was submitted on 27 Sep 2024
42 points (100.0% liked)

Linux

5184 readers
138 users here now

A community for everything relating to the linux operating system

Also check out !linux_memes@programming.dev

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 1 year ago
MODERATORS
 

cross-posted from: https://ani.social/post/6217644

you are viewing a single comment's thread
view the rest of the comments
[–] curbstickle@lemmy.dbzer0.com -1 points 1 month ago (1 children)

Yes.

Its nowhere near the risk that was claimed.

[–] Toes@ani.social 4 points 1 month ago (2 children)

Basically an unauthenticated perl interpreter with root open to the network by default in most configurations across a couple decades.

It's about as bad as it can be?

[–] curbstickle@lemmy.dbzer0.com 3 points 1 month ago

Compared to the original claim that it was kernel level and spread across literally everything?

No, no its not as bad as it was originally claimed.

Is it bad? Yes. Is it kernel level bad? No. It can easily be mitigated before a fix is out by blocking 631 and dns-sd traffic. It is not as bad as it was claimed to be.

[–] progandy@feddit.org 1 points 1 month ago

Is it common for cups to run as root? It should have its own user, but that is still not good.