So, this is exploitable if you're running an SNES SPC backend in gstreamer, on a linux workstation.
That's a big stretch, and a lot of hype for this "0-day". How many people are going to be realistically affected by this? Why is arstechnica making such hype about it?
Yes, it's novel that someone's been able to break out of gstreamer's sandbox using unimplemented (or poorly-implemented) 65816 opcodes, but that's about as far as it goes.
Thankfully, my Calculate (Gentoo) Linux KDE desktop with a VLC backend is completely unaffected by this "0-day", and everything on my network is safe.
The base problem is that browsers are trying to be friendly by auto-downloading or auto-playing media files.
If neither of those happened, these exploits could not be automated (though social engineering would always be an option).
Heck, the download itself is not a problem. The problem is that the DEs, in an attempt at being "helpful" detect and parse every new file for inclusion into their search functionality. And the parsing in this instance gets done by passing the file through gstreamer, and away we go again.
Comments
So, this is exploitable if you're running an SNES SPC backend in gstreamer, on a linux workstation.
That's a big stretch, and a lot of hype for this "0-day". How many people are going to be realistically affected by this? Why is arstechnica making such hype about it?
Yes, it's novel that someone's been able to break out of gstreamer's sandbox using unimplemented (or poorly-implemented) 65816 opcodes, but that's about as far as it goes.
Thankfully, my Calculate (Gentoo) Linux KDE desktop with a VLC backend is completely unaffected by this "0-day", and everything on my network is safe.
I think Debian & Ubuntu installs this by default for some crazy reason.
Maybe it's time Linux distros learn what OpenBSD learned 10 years ago: more packages more problems
This SNES SPC backend is installed by in Ubuntu and Fedora (afaik, almost every distro that ships Gnome, since Gstreamer is a Gnome dependency).
So yeah, kinda of a hype however the target is pretty big.
The base problem is that browsers are trying to be friendly by auto-downloading or auto-playing media files.
If neither of those happened, these exploits could not be automated (though social engineering would always be an option).
Heck, the download itself is not a problem. The problem is that the DEs, in an attempt at being "helpful" detect and parse every new file for inclusion into their search functionality. And the parsing in this instance gets done by passing the file through gstreamer, and away we go again.
This is idiocy on par with autorun!