• JelleWho@lemmy.world
    link
    fedilink
    English
    arrow-up
    26
    ·
    7 hours ago

    For a second I though this was something bad for my computer. But is mainly a server permissions issue it seems. Will patch my server when I’m home though

    • drkt@scribe.disroot.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 hour ago

      What do you mean? If you use Linux on your computer, it’s also relevant. Any program can quietly drop a root shell from any privilege level in 10 lines of python.

      • ipp0@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        9
        ·
        1 hour ago

        This attack must be run locally. The attacker must already have user access. They can then escalate privileges using this. Meaning your box must already be compromised for this to work. Still serious, but no need to panic in most cases.

        • drkt@scribe.disroot.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 minutes ago

          /c/selfhosted moment

          Sure don’t patch a quiet and easy root shell escalation because it is, by itself, not a remote exploit. I sure do hope you trust every single piece of software running on your computer.