-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 UCB-security,
I Qualys has recently released information about a vulnerability in the GNU C Library or glib. There is a remote code execution risk due to this vulnerability. An attacker who exploits this issue can gain complete control of the compromised system. What versions and operating systems are affected? The first vulnerable version of the GNU C Library affected by this is glibc-2.2, released on November 10, 2000. Qualys identified a number of factors that mitigate the impact of this bug. In particular, they discovered that it was fixed on May 21, 2013 (between the releases of glibc-2.17 and glibc-2.18). Unfortunately, it was not recognized as a security threat; as a result, most stable and long-term-support distributions were left exposed including Debian 7 (wheezy), Red Hat Enterprise Linux 6 & 7, CentOS 6 & 7, Ubuntu 12.04, for example. Is the risk real? During Qualys's testing, they developed a proof-of-concept in which they send a specially created e-mail to a mail server and can get a remote shell to the Linux machine. This bypasses all existing protections (like ASLR, PIE and NX) on both 32-bit and 64-bit systems. What can be done to mitigate the risk? The best way to mitigate the risk is to apply a patch from your Linux vendor. Please patch as soon as possible. Relevant links: https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability http://ma.ttias.be/critical-glibc-update-cve-2015-0235-gethostbyname-calls/ http://www.openwall.com/lists/oss-security/2015/01/27/9 Thanks jake-F - -- - ----------------------------------------------------------------------- Jake-F Harwood Security OPS, ISP University of California, Berkeley Cell (510) 390-2580 office (510) 643-8241 "Who is this General Failure and why is he reading my hard drive?" -F - -------------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- iQGcBAEBAgAGBQJUyBbAAAoJELAGZxF1pG5KIqQL+wSFdrZTau7m6Zb8iIoi5Jxu ra1OMI3M/iHBdAVlzv55QtDLMS8NVAYnhKz3+ym7XkP2+GCxnvB3A1BZcfVSYQAx wm5NFMhgkRfjY7ln6rBOHfj3y0B3c/CwNzkctnz9Qtse67YcEVNJH360PKfy4c8j Yuu4sm2Ma/LVhhytQNYTXJxRwZOmNIj0dhywp49Rp1GpVvEeLbJeydkKEAiodlep xEIlXSV7AzKvb+wYB/vwCXLD5NpI+sALtHtuvHGcRsOcTNHeo5gNVe79caQl5fiX 6nWX/WvVAzAR/ZkcM7ChsieAWtWUoVBuq6+g22NCCf4FUaAEkdK8APc3pYJlVAdk BBjkYsSFDlKw3zjFLIAoem+7tifwg9khyDW7fkFw6R0zNnGCYUDf8+sqx83afJz9 SahKIngiTFdVslQMNMLQwCw7t2jPHmTgRFwfGSkDmWddSvpLELsVrvIEzDsl/nwM Bf8KH946bhQanHFcLVQsZ+c6inRr9RehMyHIJZUc9g== =pngS -----END PGP SIGNATURE----- ------------------------------------------------------------------------- The following was automatically added to this message by the list server: To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site: http://micronet.berkeley.edu Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet. This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.
