Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror

Submission + - regreSSHion: Unauthenticated Remote Root Vulnerability in OpenSSH Server (qualys.com)

Artem S. Tashkinov writes: The Qualys Threat Research Unit (TRU) has discovered a Remote Unauthenticated Code Execution (RCE) vulnerability in OpenSSH’s server (sshd) in glibc-based Linux systems. CVE assigned to this vulnerability is CVE-2024-6387. The vulnerability, which is a signal handler race condition in OpenSSH’s server (sshd), allows unauthenticated remote code execution (RCE) as root on glibc-based Linux systems; that presents a significant security risk. This race condition affects sshd in its default configuration.

Based on searches using Censys and Shodan, we have identified over 14 million potentially vulnerable OpenSSH server instances exposed to the Internet. Anonymized data from Qualys CSAM 3.0 with External Attack Surface Management data reveals that approximately 700,000 external internet-facing instances are vulnerable. This accounts for 31% of all internet-facing instances with OpenSSH in our global customer base.

In our security analysis, we identified that this vulnerability is a regression of the previously patched vulnerability CVE-2006-5051, which was reported in 2006. A regression in this context means that a flaw, once fixed, has reappeared in a subsequent software release, typically due to changes or updates that inadvertently reintroduce the issue. This incident highlights the crucial role of thorough regression testing to prevent the reintroduction of known vulnerabilities into the environment. This regression was introduced in October 2020 (OpenSSH 8.5p1).

Submission + - First person saved by a police drone in Canada (theverge.com)

AchilleTalon writes: As the US continues to grapple with the idea of letting drones fly through the country's airspace, our neighbors to the north have reported a new milestone for unmanned aerial technology: the first life saved using a drone. The Royal Canadian Mounted Police in the province of Saskatchewan announced yesterday that they successfully used the small Draganflyer X4-ES helicopter drone to locate and treat an injured man whose car had flipped over in a remote, wooded area in near-freezing temperatures. Zenon Dragan, president and founder of the Draganfly company that makes the drone, said in a statement: "to our knowledge, this is the first time that a life may have been saved with the use of a sUAS (small Unmanned Aerial System) helicopter."

Slashdot Top Deals

You know you've been spending too much time on the computer when your friend misdates a check, and you suggest adding a "++" to fix it.

Working...