Linux Vulnerability Announced, Details Kept Secret  [Solved]

For interesting topics. But remember this is a Linux Forum. Do not post offensive topics that are meant to cause trouble with other members or are derogatory towards people of different genders, race, color, minors (this includes nudity and sex), politics or religion. Let's try to keep peace among the community and for visitors.

No spam on this or any other forums please! If you post advertisements on these forums, your account may be deleted.

Do not copy and paste entire or even up to half of someone else's words or articles into posts. Post only a few sentences or a paragraph and make sure to include a link back to original words or article. Otherwise it's copyright infringement.

You can talk about other distros here, but no MX bashing. You can email the developers of MX if you just want to say you dislike or hate MX.
Message
Author
User avatar
siamhie
Global Moderator
Posts: 3216
Joined: Fri Aug 20, 2021 5:45 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#11 Post by siamhie »

If you don't want to waste 24 minutes of your time watching his video then head over here to read what he is reading verbatim.

Attacking UNIX Systems via CUPS, Part I
This is my Fluxbox . There are many others like it, but this one is mine. My Fluxbox is my best friend. It is my life.
I must master it as I must master my life. Without me, my Fluxbox is useless. Without my Fluxbox, I am useless.

User avatar
CharlesV
Global Moderator
Posts: 7059
Joined: Sun Jul 07, 2019 5:11 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#12 Post by CharlesV »

*QSI = Quick System Info from menu (Copy for Forum)
*MXPI = MX Package Installer
*Please check the solved checkbox on the post that solved it.
*Linux -This is the way!

User avatar
kernelkurtz
Posts: 32
Joined: Mon Sep 18, 2017 1:13 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#13 Post by kernelkurtz »

he has in the last few years become more extremist and reactionary than he's ever been in the past

This gets said by more and more people, about more and more people.

I will just point out that there is a valid alternative explanation. Which is that people don't change all that much, but the culture has shifted dramatically to 'the center' under their feet, leaving them looking extremist for views they've always held and the actions they take as a result. I believe it happened to Mr. Snowden.

To keep things almost back on topic, I contribute this:

https://en.wikipedia.org/wiki/Alan_Cox_ ... rogrammer)

User avatar
DukeComposed
Posts: 1289
Joined: Thu Mar 16, 2023 1:57 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#14 Post by DukeComposed »

kernelkurtz wrote: Thu Sep 26, 2024 10:07 pm he has in the last few years become more extremist and reactionary than he's ever been in the past

This gets said by more and more people, about more and more people.

I will just point out that there is a valid alternative explanation. Which is that people don't change all that much, but the culture has shifted dramatically to 'the center' under their feet, leaving them looking extremist for views they've always held and the actions they take as a result.
That theory asserts that the Overton window is shifting to the center. If this were true, emerging social and fiscal policies should be moderate right about now and there's ample evidence to suggest that's not the case.

In this specific situation, the BLM and antifa movements in the U. S. in 2020 hit Bryan Lund close to home, literally and figuratively, and it's some people's opinion that this spooked him enough to make him start doubling down on his political stance to the point that he is largely unable or unwilling to keep it separate from his tech reporting. This thread reminded me of the video "Linux Sucks" Sucks, which I revisited tonight.

It reminded me of Bryan Lund's original "I have a politics website and a tech website, let's keep them separate" post and how readily he ignores this directive. My point remains: what he considers journalism shouldn't be mistaken for actual journalism and people need to be very, very careful when consuming his content. He has an agenda, moreso than most.

To that end, let me amend my statement from "he has in the last few years become more extremist and reactionary than he's ever been in the past" to "he has in the last few years become more open and brazen about his extremist and reactionary opinions and conspiracy theories that he has probably always had".

User avatar
MikeR
Posts: 195
Joined: Sun Jun 25, 2023 6:42 am

Re: Linux Vulnerability Announced, Details Kept Secret

#15 Post by MikeR »

It looks like a patch is available, at least for Ubuntu and derivatives (Mint...): https://ubuntu.com/security/notices/USN-7043-1
Old RSTS hack
Registered Linux user #542196

User avatar
mxrd
Posts: 208
Joined: Fri Jul 10, 2020 7:00 am

Re: Linux Vulnerability Announced, Details Kept Secret

#16 Post by mxrd »

So to speak, for first aid it in a first step would be sufficient to completely deinstall cups and close port 631?
(i deinstalled cups for testing, in a vm and on bare metal, and on latter closed 631, and no negativ effect until now; )

User avatar
Eadwine Rose
Administrator
Posts: 14429
Joined: Wed Jul 12, 2006 2:10 am

Re: Linux Vulnerability Announced, Details Kept Secret

#17 Post by Eadwine Rose »

Still able to print in all ways?
MX-23.6_x64 July 31 2023 * 6.1.0-34amd64 ext4 Xfce 4.20.0 * 8-core AMD Ryzen 7 2700
Asus TUF B450-Plus Gaming UEFI * Asus GTX 1050 Ti Nvidia 535.216.01 * 2x16Gb DDR4 2666 Kingston HyperX Predator
Samsung 870EVO * Samsung S24D330 & P2250 * HP Envy 5030

User avatar
mxrd
Posts: 208
Joined: Fri Jul 10, 2020 7:00 am

Re: Linux Vulnerability Announced, Details Kept Secret

#18 Post by mxrd »

Eadwine Rose wrote: Sat Sep 28, 2024 5:10 am Still able to print in all ways?
sorry, of course to consider,
if one has installed a printer urgently needed of course not to do it this way, or carefully
ponder about this method

but i don't need printing this way because of the special demands of the printer type i didnt get it to work, so i print
(that seldom that i really need it ) with the parrallel installed ifjdoiawng- OS (don't want to mention it in this forum :p )

And, oc all imho: considering the security under this circumstances it looks for me to be worth to do it this way,
base installing of cups looks easy with synaptic, so when vulnerabilitiy-situation will alleviate it looks like
installing again is a breeze?!?

User avatar
dreamer
Posts: 878
Joined: Sun Oct 15, 2017 11:34 am

Re: Linux Vulnerability Announced, Details Kept Secret

#19 Post by dreamer »

The severe vulnerability 9.9/10 doesn’t impact basic printing and scanning.

The easiest solution is to uninstall the cups-browsed package. I always do this on my personal snapshots. It doesn’t affect printing or scanning. If you don’t want to uninstall the cups-browsed package you can disable the service while you wait for patches to be delivered.

Red Hat has a good write-up:
https://www.redhat.com/en/blog/red-hat- ... rabilities
Note to self and others: SysVinit is a good option. However if you run into problems try with systemd first. This applies to AppImages, Flatpaks, GitHub packages and even some Debian packages.

User avatar
AK-47
Developer
Posts: 1190
Joined: Sun Mar 24, 2019 7:04 pm

Re: Linux Vulnerability Announced, Details Kept Secret

#20 Post by AK-47 »

Eadwine Rose wrote: Thu Sep 26, 2024 1:27 pmTo be honest, I don't care about this sort of stuff on who did what and when. You use the computer, you are responsible.
Speaking as a dev, if only modern day computers and software were still that simple...

Post Reply

Return to “General”