me: "CVSS 9.9 affecting BSD and Linux? That sounds like Coreutils then."
@orman: "Well it's GNU/Something Fundamental. It's an unauthenticated network RCE."
me: *screams internally, whines externally*
Simone Margaritelli (@evilsocket) on X
* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago. * Full disclosure happening in less than 2 weeks (as agreed with devs). * Still no CVE assigned (there should be at least 3, possibly 4, ideally 6). * Still no working fix. * Canonical, RedHat and