Navigate Select ESC Close

The 9.9 CVE Linux RCE Security Bug!!

2024-09-29 Science & Technology
59.1k
1.3k
379
ThePrimeTime
ThePrimeTime
1.1m subscribers

Unlock all features

FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.

Description

Recorded live on twitch, GET IN ### Article https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ By: Simone Margaritelli | https://x.com/evilsocket ### Guest Low Level Learning | https://www.youtube.com/c/lowlevellearning ### My Stream https://twitch.tv/ThePrimeagen ### Best Way To Support Me Become a backend engineer. Its my favorite site https://boot.dev/?promo=PRIMEYT This is also the best way to support me is to support yourself becoming a better backend engineer. MY MAIN YT CHANNEL: Has well edited engineering videos https://youtube.com/ThePrimeagen Discord https://discord.gg/ThePrimeagen Have something for me to read or react to?: https://www.reddit.com/r/ThePrimeagen Kinesis Advantage 360: https://bit.ly/Prime-Kinesis Get production ready SQLite with Turso: https://turso.tech/deeznuts

Top Comments (10)

@PassifloraCerulea 2024-09-29

Back in the early-mid aughts, CUPS was a breath of fresh air compared to Windows network printer setup (speaking as a former admin). Hadn't thought about it since then. Sorry to hear that it was written with so little thought to security. Rust peeps will have their hands full if they really do try to rewrite the world of system software, including things like CUPS which are boring but extremely important for some people.

24 10 replies
@imjustsomepersonontheinternet 2024-09-29

The availability point Prime made is actually really interesting. Typically, in the score, if you can have a higher impact on availability, it's a worse score. But he makes a good point about how impacting availability could cause the exploitation to be discovered sooner.

11
@71Jay17 2024-10-02

Great video guys. Always know we are in for a good time when low level and prime get together

0
@JPs-q1o 2024-09-30

Awesome coverage of this bug and the accompanying discussion. It's what I've come to expect from this channel.

0
@scar6073 2024-09-29

This is why the kernel should have been made in Python

277 21 replies
@sokrar 2024-09-30

it is a 9.9, and you can take 5 minutes to look at it and discard it if you are not affected. Like you could discard log4shell in many cases.

7
@roamingremote 2024-10-17

your highlighting methods drive me crazy

0
@yon2004 2024-09-30

I'm fairly sure that CUPS is used in MacOS and mac users do love to print.

6 3 replies
@bobert3335 2024-09-30

CIA is most easily understood in regards to data: Confidentiality = Attackers can read the data Integrity = Attackers can change the data (but not necessarily read it) Availability = Attacker can prevent legitimate users from accessing the data

3 2 replies
@Ch0rr1s 2024-09-30

CVSS - Cascading vucking style sheets :)

1

Unlock the Data Inside
Turn Videos into Knowledge

  • Get FREE 10/day: transcripts, summaries, chats
  • Chat with videos, export text & PDF
  • $1 free API credit for RAG, chatbots & research

Free forever plan • All features unlocked

App screenshot