You bring up a question: why worry about it if the OS is running off a bootable CD? The OS itself can not be corrupted by an external attack.

For a third party to attack from the internet via this avenue, he would have to guess which version of Knoppix is being run, then how the particular user is storing his or her data on which kind of nonvolatile memory. It seems like an awful lot of work, for what?