• TreasureOP
      arrow-up
      23
      arrow-down
      0
      ·
      22 days ago
      link
      fedilink

      This link should be working.

      Quoting from the OP tweet:

      * Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago.
      * Full disclosure happening in less than 2 weeks (as agreed with devs).
      * Still no CVE assigned (there should be at least 3, possibly 4, ideally 6).
      * Still no working fix.
      * Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot.
      * Devs are still arguing about whether or not some of the issues have a security impact.

      I’ve spent the last 3 weeks of my sabbatical working full time on this research, reporting, coordination and so on with the sole purpose of helping and pretty much only got patronized because the devs just can’t accept that their code is crap - responsible disclosure: no more.

      • LiveLMEnglish
        arrow-up
        9
        arrow-down
        0
        ·
        22 days ago
        link
        fedilink

        Seems like he not only deleted the Tweet but also protected his whole account Very weird

          • caseyweederman
            arrow-up
            1
            arrow-down
            0
            ·
            22 days ago
            link
            fedilink

            I’ve noticed Canonical replaced their score breakdown with an ad for their paid services.

            • Possibly linuxEnglish
              arrow-up
              2
              arrow-down
              0
              ·
              22 days ago
              link
              fedilink

              That probably means this is closer to a publicity stunt. I’ll just wait until there is more information.