Linux admins, get patching. New vulnerability found in Glibc

Linux admins, get patching. New vulnerability found in Glibc

Author
Discussion

TonyRPH

Original Poster:

12,977 posts

169 months

Wednesday 28th January 2015
quotequote all
This is quite a bad one.

Qualys Security Advisory CVE-2015-0235

GHOST: glibc gethostbyname buffer overflow

mw88

1,457 posts

112 months

Wednesday 28th January 2015
quotequote all
Joy.. 8 Production servers, 2 dev servers and 2 Ubuntu desktops to patch.

Tomorrow's going to be fun!

cornet

1,469 posts

159 months

Wednesday 28th January 2015
quotequote all
mw88 said:
Joy.. 8 Production servers, 2 dev servers and 2 Ubuntu desktops to patch.

Tomorrow's going to be fun!
Is that all... wink

We've patched 120+ servers today... Don't forget to restart any services that use gethostbyname()

onomatopoeia

3,472 posts

218 months

Friday 30th January 2015
quotequote all
cornet said:
Is that all... wink

We've patched 120+ servers today... Don't forget to restart any services that use gethostbyname()
exim seems the only common one that is remotely exploitable from what I've been reading. Apache, mysql/maria etc appear in the clear.

Qualys seem to have done an awful lot of work on this before it was made public on Tuesday, the advisory was an impressive piece of work.