OpenSSH: race condition in sshd allows remote code execution
OpenSSH: race condition in sshd allows remote code execution
A severe vulnerability in OpenSSH, dubbed "regreSSHion" (CVE-2024-6387), has been discovered by the Qualys Threat Research Unit, potentially exposing
![OpenSSH: race condition in sshd allows remote code execution](https://lemmy.ml/pictrs/image/2e697b3c-66dc-461b-8ae9-73b2076759f4.jpeg?format=webp&thumbnail=256)
A severe vulnerability in OpenSSH, dubbed "regreSSHion" (CVE-2024-6387), has been discovered by the Qualys Threat Research Unit, potentially exposing
You're viewing a single thread.
Last I read about it it required connecting for 6-7 hours continuously on 32bit systems, and it's unknown how long it would take on 64bit.
17 0 ReplyYeah, exactly. Very impracticable.
3 0 ReplyBut, eventually exploitable is still a pretty major concern for anybody who has systems running longer than a few days at a time.
5 0 ReplyTrue, an RCE is always a serious thing. Just saying it's not exactly catastrophic like others have been more so.
3 0 ReplyI can’t imagine any system of influence running an exposed ssh without some further protection from connection abuse like fail2ban.
2 0 Reply
Reminds me of the node-ip guy making thn repo read only because of amateur researchers filling up cve s
1 0 Reply