-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

UCB-security,

I Qualys has recently released information about a vulnerability in
the GNU C Library or glib.

There is a remote code execution risk due to this vulnerability. An
attacker who exploits this issue can gain complete control of the
compromised system.


What versions and operating systems are affected?

The first vulnerable version of the GNU C Library affected by this is
glibc-2.2, released on November 10, 2000. Qualys identified a number
of factors that mitigate the impact of this bug. In particular, they
discovered that it was fixed on May 21, 2013 (between the releases of
glibc-2.17 and glibc-2.18). Unfortunately, it was not recognized as a
security threat; as a result, most stable and long-term-support
distributions were left exposed including Debian 7 (wheezy), Red Hat
Enterprise Linux 6 & 7, CentOS 6 & 7, Ubuntu 12.04, for example.

Is the risk real?

During Qualys's testing, they developed a proof-of-concept in which
they send a specially created e-mail to a mail server and can get a
remote shell to the Linux machine. This bypasses all existing
protections (like ASLR, PIE and NX) on both 32-bit and 64-bit systems.


What can be done to mitigate the risk?

The best way to mitigate the risk is to apply a patch from your Linux
vendor.

Please patch as soon as possible.

Relevant links:

https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability


http://ma.ttias.be/critical-glibc-update-cve-2015-0235-gethostbyname-calls/

http://www.openwall.com/lists/oss-security/2015/01/27/9

Thanks

jake-F

- -- 
- -----------------------------------------------------------------------
Jake-F Harwood                       Security OPS, ISP
                             University of California, Berkeley


                                           Cell (510) 390-2580
                                         office (510) 643-8241

   "Who is this General Failure and why is he reading my hard drive?" -F
- --------------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----

iQGcBAEBAgAGBQJUyBbAAAoJELAGZxF1pG5KIqQL+wSFdrZTau7m6Zb8iIoi5Jxu
ra1OMI3M/iHBdAVlzv55QtDLMS8NVAYnhKz3+ym7XkP2+GCxnvB3A1BZcfVSYQAx
wm5NFMhgkRfjY7ln6rBOHfj3y0B3c/CwNzkctnz9Qtse67YcEVNJH360PKfy4c8j
Yuu4sm2Ma/LVhhytQNYTXJxRwZOmNIj0dhywp49Rp1GpVvEeLbJeydkKEAiodlep
xEIlXSV7AzKvb+wYB/vwCXLD5NpI+sALtHtuvHGcRsOcTNHeo5gNVe79caQl5fiX
6nWX/WvVAzAR/ZkcM7ChsieAWtWUoVBuq6+g22NCCf4FUaAEkdK8APc3pYJlVAdk
BBjkYsSFDlKw3zjFLIAoem+7tifwg9khyDW7fkFw6R0zNnGCYUDf8+sqx83afJz9
SahKIngiTFdVslQMNMLQwCw7t2jPHmTgRFwfGSkDmWddSvpLELsVrvIEzDsl/nwM
Bf8KH946bhQanHFcLVQsZ+c6inRr9RehMyHIJZUc9g==
=pngS
-----END PGP SIGNATURE-----

 
-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from 
its mailing list and how to find out about upcoming meetings, please visit the 
Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the 
list's archives can be browsed and searched on the Internet.  This means these 
messages can be viewed by (among others) your bosses, prospective employers, 
and people who have known you in the past.

Reply via email to