create account

The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems by robrigo

View this thread on: hive.blogpeakd.comecency.com
· @robrigo ·
$448.44
The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems
If you are have any machines running Linux, OpenBSD, NetBSD, FreeBSD or Solaris operating systems, on i386 or amd64, you should patch the system as soon as possible to prevent abuse of a local privilege escalation bug called The Stack Clash. Following responsible disclosure, all of the vulnerable systems should have the necessary patches made available today.

The exploit works by "colliding, or clashing, the stack with another memory region," allowing the execution of arbitrary code to occur if an attacker has access to your local file system already as an unprivileged user.

More information can be found here:
 -  https://blog.qualys.com/securitylabs/2017/06/19/the-stack-clash
 - https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt

<center>![](https://steemitimages.com/DQmSkG9z7kiVVTXJsTkjQHAgA89YdABzwFBPBh4bBqLEjYL/image.png)</center>
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 192 others
👎  
properties (23)
authorrobrigo
permlinkthe-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems
categorysecurity
json_metadata{"tags":["security","vulnerability","linux","witness","operations"],"image":["https://steemitimages.com/DQmSkG9z7kiVVTXJsTkjQHAgA89YdABzwFBPBh4bBqLEjYL/image.png"],"links":["https://blog.qualys.com/securitylabs/2017/06/19/the-stack-clash","https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt"],"app":"steemit/0.1","format":"markdown"}
created2017-06-19 18:18:51
last_update2017-06-19 18:18:51
depth0
children15
last_payout2017-06-26 18:18:51
cashout_time1969-12-31 23:59:59
total_payout_value394.496 HBD
curator_payout_value53.939 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length859
author_reputation36,085,196,360,202
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,282,483
net_rshares23,587,430,104,329
author_curate_reward""
vote details (257)
@anri-avgustino ·
$2.24
Good article, thank you. I never trusted Linux, you finally armed me. But I really liked your Super Task subscribed to your blog. I, too, want to make the world better, you're done! "Working to build a beautiful and free future for all people on Earth." @robrigo
👍  
properties (23)
authoranri-avgustino
permlinkre-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t213039137z
categorysecurity
json_metadata{"tags":["security"],"users":["robrigo"],"app":"steemit/0.1"}
created2017-06-19 21:30:42
last_update2017-06-19 21:30:42
depth1
children0
last_payout2017-06-26 21:30:42
cashout_time1969-12-31 23:59:59
total_payout_value1.678 HBD
curator_payout_value0.557 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length262
author_reputation14,864,475,430,554
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,296,098
net_rshares118,626,780,626
author_curate_reward""
vote details (1)
@billbutler ·
$7.19
voted, resteemed, followed
👍  ,
properties (23)
authorbillbutler
permlinkre-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t215328585z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-06-19 21:53:30
last_update2017-06-19 21:53:30
depth1
children0
last_payout2017-06-26 21:53:30
cashout_time1969-12-31 23:59:59
total_payout_value6.848 HBD
curator_payout_value0.341 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length26
author_reputation31,319,794,402,837
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,297,538
net_rshares381,659,776,543
author_curate_reward""
vote details (2)
@correctdrop ·
Great post man!
properties (22)
authorcorrectdrop
permlinkre-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t232719595z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-06-19 23:27:21
last_update2017-06-19 23:27:21
depth1
children0
last_payout2017-06-26 23:27:21
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length15
author_reputation-46,634,556,923
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,303,678
net_rshares0
@cryptodata ·
$2.36
Thanks for the warning! You never know what new exploits are going to pop up. It's always nice to have people like you monitoring them and keeping us safe :)
👍  
properties (23)
authorcryptodata
permlinkre-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t191256096z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-06-19 19:12:54
last_update2017-06-19 19:12:54
depth1
children0
last_payout2017-06-26 19:12:54
cashout_time1969-12-31 23:59:59
total_payout_value1.826 HBD
curator_payout_value0.536 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length157
author_reputation1,577,806,466,314
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,286,494
net_rshares124,870,295,396
author_curate_reward""
vote details (1)
@fatpandadesign ·
$2.37
Great share and definitely important for me...time to do some research. Thank you for the heads up!
👍  
properties (23)
authorfatpandadesign
permlinkre-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t185501730z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-06-19 18:55:03
last_update2017-06-19 18:55:03
depth1
children0
last_payout2017-06-26 18:55:03
cashout_time1969-12-31 23:59:59
total_payout_value1.774 HBD
curator_payout_value0.591 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length99
author_reputation5,141,975,201,961
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,285,243
net_rshares124,870,295,396
author_curate_reward""
vote details (1)
@full-steem-ahead ·
$5.85
I want to emphasize this is only an issue if an attacker manages to gain login access to your system. Although I totally agree this vulnerability should be given a high priority & fixed by applying the appropriate patches, it would be more concerning to learn login access to my systems were possible that are a prerequisite for the "stack-clash" exploit to be performed.

Additionally it may take a few days for your distro to provide the patch for your OS version. 

Let this be a wakeup call to those of you who haven't secured your systems by A) denying root ssh access and B) allowing only public key logins. Those of course are only 2 of the many other precautions all node operators should have in place. Make sure all unessential network listeners are disabled, and you use fail2ban on any open ports. 

I also highly recommend you employ the api_access control for your cli_wallet, and only expose the rpc-endpoint to the network through a proxy or not at all externally.
👍  ,
properties (23)
authorfull-steem-ahead
permlinkre-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t233501743z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-06-19 23:35:00
last_update2017-06-19 23:35:00
depth1
children0
last_payout2017-06-26 23:35:00
cashout_time1969-12-31 23:59:59
total_payout_value4.394 HBD
curator_payout_value1.460 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length980
author_reputation30,177,498,572,933
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,304,178
net_rshares313,470,465,714
author_curate_reward""
vote details (2)
@inviterx ·
$0.97
Thanks for this security advise...Will do so
👍  
properties (23)
authorinviterx
permlinkre-robrigo-2017625t193453324z
categorysecurity
json_metadata{"tags":"security","app":"esteem/1.4.5","format":"markdown+html","community":"esteem"}
created2017-06-25 14:05:33
last_update2017-06-25 14:05:33
depth1
children0
last_payout2017-07-02 14:05:33
cashout_time1969-12-31 23:59:59
total_payout_value0.720 HBD
curator_payout_value0.251 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length44
author_reputation371,803,882,756
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries
0.
accountesteemapp
weight500
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id6,045,625
net_rshares93,144,555,966
author_curate_reward""
vote details (1)
@randowhale ·
$0.27
This post received a 32% upvote from @randowhale thanks to @robrigo!  For more information, [click here](https://steemit.com/steemit/@randowhale/introducing-randowhale-will-you-get-the-100-vote-give-it-a-shot)!
👍  ,
properties (23)
authorrandowhale
permlinkre-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t184620
categorysecurity
json_metadata"{"format": "markdown", "app": "randowhale/0.1"}"
created2017-06-19 18:46:24
last_update2017-06-19 18:46:24
depth1
children0
last_payout2017-06-26 18:46:24
cashout_time1969-12-31 23:59:59
total_payout_value0.270 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length210
author_reputation47,657,457,485,459
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,284,558
net_rshares14,277,170,719
author_curate_reward""
vote details (2)
@satfit ·
@robrigo thanks buddy for this usefull info upvoted u and follow 
#upvot me too
👍  
properties (23)
authorsatfit
permlinkre-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t182153747z
categorysecurity
json_metadata{"tags":["upvot","security"],"users":["robrigo"],"app":"steemit/0.1"}
created2017-06-19 18:22:00
last_update2017-06-19 18:22:00
depth1
children0
last_payout2017-06-26 18:22:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length79
author_reputation2,001,092,299,106
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,282,707
net_rshares0
author_curate_reward""
vote details (1)
@satfit ·
@robrigo  how will i know dt my system is vulnerable to this exploit
👍  
properties (23)
authorsatfit
permlinkre-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t182342109z
categorysecurity
json_metadata{"tags":["security"],"users":["robrigo"],"app":"steemit/0.1"}
created2017-06-19 18:23:48
last_update2017-06-19 18:23:48
depth1
children2
last_payout2017-06-26 18:23:48
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length68
author_reputation2,001,092,299,106
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,282,871
net_rshares159,503,743
author_curate_reward""
vote details (1)
@robrigo ·
If you're running a linux distro it will be vulnerable. Update your system and you should be good to go!
properties (22)
authorrobrigo
permlinkre-satfit-re-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t182632404z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-06-19 18:26:33
last_update2017-06-19 18:26:33
depth2
children1
last_payout2017-06-26 18:26:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length104
author_reputation36,085,196,360,202
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,283,080
net_rshares0
@satfit ·
Thanks buddy an upvote will be very helpful
properties (22)
authorsatfit
permlinkre-robrigo-re-satfit-re-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t183501718z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-06-19 18:35:06
last_update2017-06-19 18:35:06
depth3
children0
last_payout2017-06-26 18:35:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length43
author_reputation2,001,092,299,106
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,283,688
net_rshares0
@steemitboard ·
Congratulations @robrigo! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

[![](https://steemitimages.com/70x80/http://steemitboard.com/notifications/votes.png)](http://steemitboard.com/@robrigo) Award for the number of upvotes

Click on any badge to view your own Board of Honnor on SteemitBoard.
For more information about SteemitBoard, click [here](https://steemit.com/@steemitboard)

If you no longer want to receive notifications, reply to this comment with the word `STOP`

By upvoting this notification, you can help all Steemit users. Learn how [here](https://steemit.com/steemitboard/@steemitboard/http-i-cubeupload-com-7ciqeo-png)!
properties (22)
authorsteemitboard
permlinksteemitboard-notify-robrigo-20170620t114659000z
categorysecurity
json_metadata{"image":["https://steemitboard.com/img/notifications.png"]}
created2017-06-20 09:47:15
last_update2017-06-20 09:47:15
depth1
children0
last_payout2017-06-27 09:47:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length683
author_reputation38,975,615,169,260
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,336,202
net_rshares0
@troilo ·
I was trying to install Linux today. Now I'm hesitating. :P
👍  
properties (23)
authortroilo
permlinkre-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t182738125z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-06-19 18:27:39
last_update2017-06-19 18:27:39
depth1
children1
last_payout2017-06-26 18:27:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length59
author_reputation24,733,619,722,723
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,283,147
net_rshares0
author_curate_reward""
vote details (1)
@robrigo ·
So long as you fully patch the machine you should be good to go!
properties (22)
authorrobrigo
permlinkre-troilo-re-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t182849884z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-06-19 18:28:51
last_update2017-06-19 18:28:51
depth2
children0
last_payout2017-06-26 18:28:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length64
author_reputation36,085,196,360,202
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,283,238
net_rshares0