An official website of the United States government
Here's how you know
Official websites use .mil
A
.mil
website belongs to an official U.S. Department of Defense organization in the United States.
Secure .mil websites use HTTPS
A
lock (
lock
)
or
https://
means you’ve safely connected to the .mil website. Share sensitive information only on official, secure websites.
Skip to main content (Press Enter).
Toggle navigation
75th U.S. Army Reserve Innovation Command
Make Ready!
75th U.S. Army Reserve Innovation Command
Search
Search 75th U.S. Army Reserve Innovation Command:
Search
Search 75th U.S. Army Reserve Innovation Command:
Search
Home
About
Leadership
Mission & Vision
Where We Innovate
News
MAJ Rubins Award
Talent Management
Civilian Partnerships
Innovation Support Request
Contact Us
Home
Test Page
Playlist:
Search Results
Video by Courtesy
Player Embed Code:
Download
Embed
Share
Phoenix Cast [Episode 21] - Instant Reaction: Baron Samedit
U.S. Marine Corps Forces Cyberspace Command
Feb. 4, 2021 | 46:30
In this episode of Phoenix Cast, hosts John and Kyle and Rich share their instant reaction to a recently revealed vulnerability in sudo, which is a a powerful and near-ubiquitous open-source utility used on major Linux and Unix-like operating systems. How big of a deal is CVE-2021-3156 aka "Baron Samedit"? What should you do if you're vulnerable? When will all these vulnerabilities end? Stay tuned to find out...
Share your thoughts with us on Twitter: @USMC_TFPhoenix
Leave your review on Apple Podcasts.
Learn more about Baron Samedit:
https://www.deepwatch.com/blog/sudo-vulnerability/
https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit
https://www.zdnet.com/article/10-years-old-sudo-bug-lets-linux-users-gain-root-level-access/
https://www.scmagazine.com/home/security-news/network-security/one-of-the-most-beautiful-bugs-ive-seen-decade-old-sudo-bug-grants-linux-root-access/
https://aws.amazon.com/blogs/opensource/stepping-up-for-a-truly-open-source-elasticsearch/
https://www.nytimes.com/2019/12/15/technology/amazon-aws-cloud-competition.html
https://arstechnica.com/gadgets/2021/01/centos-is-gone-but-rhel-is-now-free-for-up-to-16-production-servers/
More
Tags
podcast
TF Phoenix
Task Force Phoenix
MARFORCYBER
PhoenixCast
Phoenix Cast
More
Up Next
50:52
U.S. Cyber Command Hack the Hiring Process
50:52
U.S. Cyber Command Hack the Hiring Process
1:34
MARFORCYBER Apprenticeship Program
0:45
MARFORCYBER Apprenticeship Program
01:03:59
Phoenix Cast [Episode 26] - The Phoenix Project and DevOps with Gene Kim
01:04:42
Phoenix Cast [Episode 23] - The FIRST Network Battalion
2:03
Covid-19 Vaccinations
3:13
MARFORCYBER receive COVID-19 vaccinations
2:33
MARFORCYBER receives COVID-19 vaccinations
01:16:13
Phoenix Cast [Episode 22] - Council of Colonels with Col Clearfield & Col Debish
01:02:11
Phoenix Cast [Episode 22] - Convergence in the Information Environment
Now Playing
Phoenix Cast [Episode 21] - Instant Reaction: Baron Samedit
0:40
MARFORCYBER Senior Leaders Get COVID-19 Vaccine
01:10:38
Phoenix Cast [Episode 19] - Leading Cyber Marines with Maj. Gen. Matthew G. Glavy
44:56
Phoenix Cast [Episode 15] - Work From Home
More Videos