US CISA adds ‘insane’ Linux Copy Fail flaw to watch list

0
840_aHR0cHM6Ly9wYXlsb2FkLmx1bS10cmkub3JnL2FwaS9hcnRpY2xlLWNvdmVycy9maWxlL0hJJTIwQml0aHVtYiUyMEhhY2slMjAtJTIwd2hhdCUyMGlzJTIwa25vd24lMjAoMSkuanBnP3ByZWZpeD1tZWRpYSUyRmFydGljbGUtY292ZXJz

Malicious actors with code execution capability may gain root access on Linux systems using as few as 10 lines of Python, according to a researcher.

A newly discovered vulnerability could affect most open-source major Linux distributions released since 2017, according to security researchers. 

The flaw, titled “Copy Fail,” caught the attention of the US Cybersecurity and Infrastructure Agency (CISA), who added it to the Known Exploited Vulnerabilities (KEV) catalog on Saturday, warning it poses “significant risks to the federal enterprise.”

The vulnerability can allow attackers to gain root access across a wide range of Linux systems using a 732-byte Python script, though it requires prior code execution on the system to escalate privileges.

Read more

Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

Bitte geben Sie den Coingecko Free Api Key ein, damit dieses Plugin funktioniert

Subscribe To The Latest Crypto News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.