CVE-2021-3156 - sudo vulnerability

At the time of Dirty Cow - I had a Puppet Enterprise system (that I built myself, with some help from a company called ICE in Sydney Australia to develop some manifests) - so managed it across some 160 NIX boxen, mostly Orrible [sic] Linux 5 and 6, some Solaris, Oracle VM for x86, Solaris x86 on ZFS Appliances (much as I hate Oracle - those things run rings around NetApp bang for buck) and ExaData - then they wanted me to fix it on ~35 Mac OS desktop machines - had to get desktop support to allow me SSH access to each one with “root” - and sorted (with a for loop)… yeah Macs got Dirty Cow too - but : piece of cake…

Spectre/Meltdown still haunts me - 'cause most of the NIX boxes I managed for multiple customers, haven’t been patched, 'cause the customer won’t let me patch…

The customer still running Debian 3 is an “academic” institution trying to run themselves as an Enterprise (insert sardonic laugh)… one of those Debian 3 boxes triggers our alerting system every F–KING night!

2 Likes