That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found. Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.
That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found. Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.
I don't think we're reading the same post unless you got confused by the part where he discusses the exploit not the bug.
> Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.
Compared to what? FreeBSD? Certainly not any modern desktop OS.
MSFT is investing heavily in exploit mitigations while Linux distros are probably still struggling with ASLR. https://www.blackhat.com/docs/us-16/materials/us-16-Weston-W...
shellrc and profile as well as almost all core unix tools allow running arbitrary code.
You can even bend the paths of bashrc and friends so the user can't trivially inspect them without dropping to root first (at which point, arbitrary code can trivially obtain root access too)