Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
'Grinch' Bug May Affect Most Linux Systems
Newest First  |  Oldest First  |  Threaded View
StygianAgenda
StygianAgenda,
User Rank: Strategist
12/22/2014 | 9:42:46 AM
Agreed: Grinch issue not so much
I have to totally agree.  As I've been reading over this so-called issue this morning, I'm at a loss to understand what exactly the issue is... the 'wheel' group has been designed for controlled access to the 'su' application for as long as I can remember, and so long as no user 'aside from root' are made members of the wheel group, then there *is* no issue.

Maybe I'm misinterpretting the author's intent, but it doesn't just seem to be the author of this particular article.  A great number of tech-news sites are covering this so-called issue this morning, and all of them are reporting essentially the same thing, that this is some sort of flaw.  A misconfigured service is not a flaw, but rather a poorly thought-out security measure, and as is well known, there is no patch for human-stupidity.  Either the sysadmin is competant or not.  There is no half-way or grey-area where that is concerned.  Either you know what you're doing or you don't, which *is* correctable provided the person on the receiving end of new training is competant enough to understand their training... otherwise, they're in the wrong line of work.
anon0818748824
anon0818748824,
User Rank: Apprentice
12/18/2014 | 7:37:19 PM
Grinch issue not so much
The 'so-called' grinch issue is a non issue.  There is NO flaw, let alone a bug. The kernel, the wheel group, and polkit are working as designed. No one, and I do me NO ONE, has there system setup to allow remote installation of packages or wheel access without root permissions. I am not saying it could not be setup that way, but no one does that. 

This issue is a non issue.

Cheers
Charlie Babcock
Charlie Babcock,
User Rank: Ninja
12/17/2014 | 8:17:59 PM
Visit Grinch after Christmas
No, not Heartbleed or Shellshock but still good to pre-emptively phase out of existence. Clever holiday presentation.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Developing and Testing an Effective Breach Response Plan
Whether or not a data breach is a disaster for the organization depends on the security team's response and that is based on how the team developed a breach response plan beforehand and if it was thoroughly tested. Inside this report, experts share how to: -understand the technical environment, -determine what types of incidents would trigger the plan, -know which stakeholders need to be notified and how to do so, -develop steps to contain the breach, collect evidence, and initiate recovery.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-33187
PUBLISHED: 2022-12-09
Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow an attacker with admin privilege to read sensitive information.
CVE-2022-38765
PUBLISHED: 2022-12-09
Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.
CVE-2022-41947
PUBLISHED: 2022-12-08
DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Through various features of DHIS2, an authenticated user may be able to upload a file which includes embedded javascript. The user could then potentially trick another authenticated use...
CVE-2022-41948
PUBLISHED: 2022-12-08
DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Affected versions are subject to a privilege escalation vulnerability. A DHIS2 user with authority to manage users can assign superuser privileges to themself by manually crafting an HT...
CVE-2022-23469
PUBLISHED: 2022-12-08
Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulnerability in Traefik displaying the Authorization header in its debug logs. In certain cases, if the log level is set to DEBUG, credentials provided using the Authorization header a...