• @[email protected]
    link
    fedilink
    921 year ago

    CVE-2023-2640 and CVE-2023-32629 if you don’t fancy spending an age clicking Object to all the ‘legitimate interest’ cookie shit.

    • @[email protected]
      link
      fedilink
      01 year ago

      Tip: “I still don’t care about cookies” for desktop browsers + deleting all cookies at the end of the browser session works flawlessly for me.

  • Yewb
    link
    fedilink
    271 year ago

    CVE-2023-2640

    Needs a user account on the system (even unprivledged accounts) via overlayfs

    Overlayfs allows one, usually read-write, directory tree to be overlaid onto another, read-only directory tree. All modifications go to the upper, writable layer. This type of mechanism is most often used for live CDs but there is a wide variety of other uses.

  • @BadRS
    link
    251 year ago

    Is the end of this headline “because they haven’t updated in 3 years”?

    • style99
      link
      fedilink
      101 year ago

      In this case, it’s more like the opposite. People testing the cutting edge versions of Ubuntu are the ones impacted.

  • astraeus
    link
    fedilink
    111 year ago

    Couldn’t find whether this even impacts LTS builds. Either way, seems like patching should resolve the issue

  • Yewb
    link
    fedilink
    81 year ago

    Needs a user account on the system (even unprivledged accounts) via overlayfs

    Overlayfs allows one, usually read-write, directory tree to be overlaid onto another, read-only directory tree. All modifications go to the upper, writable layer. This type of mechanism is most often used for live CDs but there is a wide variety of other uses.

  • Roq
    link
    fedilink
    61 year ago

    @leo what’s the solution, is it just the normal apt update/upgrade or something more complicated? And is it possible to know if a machine has suffered such attack at all?

    • LeoOP
      link
      fedilink
      81 year ago

      According to the Ubuntu bulletin, a simple update is sufficient.

      The Wiz announcement didn’t really go into specifics, so not sure other than normal user auditing.