Linux admins, get patching. New vulnerability found in Glibc

Linux admins, get patching. New vulnerability found in Glibc

Author
Discussion

TonyRPH

Original Poster:

13,028 posts

170 months

Wednesday 28th January 2015
quotequote all
This is quite a bad one.

Qualys Security Advisory CVE-2015-0235

GHOST: glibc gethostbyname buffer overflow

mw88

1,457 posts

113 months

Wednesday 28th January 2015
quotequote all
Joy.. 8 Production servers, 2 dev servers and 2 Ubuntu desktops to patch.

Tomorrow's going to be fun!

cornet

1,470 posts

160 months

Wednesday 28th January 2015
quotequote all
mw88 said:
Joy.. 8 Production servers, 2 dev servers and 2 Ubuntu desktops to patch.

Tomorrow's going to be fun!
Is that all... wink

We've patched 120+ servers today... Don't forget to restart any services that use gethostbyname()

onomatopoeia

3,472 posts

219 months

Friday 30th January 2015
quotequote all
cornet said:
Is that all... wink

We've patched 120+ servers today... Don't forget to restart any services that use gethostbyname()
exim seems the only common one that is remotely exploitable from what I've been reading. Apache, mysql/maria etc appear in the clear.

Qualys seem to have done an awful lot of work on this before it was made public on Tuesday, the advisory was an impressive piece of work.