Quite a few clients (esp those under compliance) are asking about this...and if Untangle is affected, if so, the steps to remedy...
Printable View
Quite a few clients (esp those under compliance) are asking about this...and if Untangle is affected, if so, the steps to remedy...
The package affected is not loaded on NGFW. Secondly the exploit requires local access to execute. Local access is root only so it does not matter since if they are on your box, they are already root.
Yeah, I just went through this myself this morning and I concur with JCoffin's assessment.
The exploit requires local access, which means root access is already attained. So this is yet another instance of you'd have to hack the box, to hack the box... It's a non-issue.