EDIT: Original post seems to have been removed, try this Nitter mirror instead.
Okay, who’s giving odds on this one coming anywhere close to living up to its billing?
https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/
Definitely interesting
Unauthenticed RCE vs all GNU/Linux systems
So this would probably be SSH related right? Otherwise what would all Linux systems have in common?
If it were SSH though, wouldn’t that ALSO include a wider blast radius than just Linux systems?
Like OpenSSH is used all over the damn place, unless I guess there’s something specific about the issue that limits it to Linux hosts for some reason?
It supposedly affects all GNU/Linux systems, there’s no fix, existed for 10 years, severity of 9.9, but there’s an “easy workaround”.
I’m curious.
If this is true (or at least plausible to the relevant people), the author of that Twitter post will probably be on the radar of any shady government agency worldwide. Not a nice situation to be in.