-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Sorry about that typo, "I" am not "Qualys" and had nothing to do with it, it was all on Qualys. As a side note, I'm not sure when we will be able to scan for this vulnerability with Nessus. From my reading even the Qualys scanner requires authentication as remote check may be unsafe in certain situations. Jake -F On 1/27/15 2:52 PM, jakef wrote: > UCB-security, > > I Qualys has recently released information about a vulnerability in > the GNU C Library or glib. > > There is a remote code execution risk due to this vulnerability. An > attacker who exploits this issue can gain complete control of the > compromised system. > > > What versions and operating systems are affected? > > The first vulnerable version of the GNU C Library affected by this is > glibc-2.2, released on November 10, 2000. Qualys identified a number > of factors that mitigate the impact of this bug. In particular, they > discovered that it was fixed on May 21, 2013 (between the releases of > glibc-2.17 and glibc-2.18). Unfortunately, it was not recognized as a > security threat; as a result, most stable and long-term-support > distributions were left exposed including Debian 7 (wheezy), Red Hat > Enterprise Linux 6 & 7, CentOS 6 & 7, Ubuntu 12.04, for example. > > Is the risk real? > > During Qualys's testing, they developed a proof-of-concept in which > they send a specially created e-mail to a mail server and can get a > remote shell to the Linux machine. This bypasses all existing > protections (like ASLR, PIE and NX) on both 32-bit and 64-bit systems. > > > What can be done to mitigate the risk? > > The best way to mitigate the risk is to apply a patch from your Linux > vendor. > > Please patch as soon as possible. > > Relevant links: > > https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability > > > http://ma.ttias.be/critical-glibc-update-cve-2015-0235-gethostbyname-calls/ > > http://www.openwall.com/lists/oss-security/2015/01/27/9 > > Thanks > > jake-F > > > > ------------------------------------------------------------------------- > The following was automatically added to this message by the list server: > > To learn more about Micronet, including how to subscribe to or unsubscribe > from its mailing list and how to find out about upcoming meetings, please > visit the Micronet Web site: > > http://micronet.berkeley.edu > > Messages you send to this mailing list are public and world-viewable, and the > list's archives can be browsed and searched on the Internet. This means > these messages can be viewed by (among others) your bosses, prospective > employers, and people who have known you in the past. > - -- - ----------------------------------------------------------------------- Jake-F Harwood Systems and Network Security, IST Security University of California, Berkeley Cell (510) 390-2580 office (510) 643-8241 "Who is this General Failure and why is he reading my hard drive?" -F - -------------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- iQGcBAEBAgAGBQJUyBjVAAoJELAGZxF1pG5KCwML/jgf0Vu4/ZzAOuHmAKTY8rDo pzZ8zcRNpXSXH7IJM5nA8n1NqiF6ll0ijbbIUkbpornAq3j3lqrLkllsMCBZf0X1 HznAf6OIm8wCcQOeC00g49PLRvVixgupKw9it1HFsSPyJ6dGEQ9nbNuFTfcrBBPQ Lix9hsxO3TFuvNLtPa3f7Eu1Wk97JSCzKfmokrGMNlE9rr2H5bX/WHVthRoj0/Aa 4uafTvi3rV8jqsjV7YMe77lj+bQxCvPUfQPBcuKCuui51e2626BZCwq17xpOZ9+7 kBdA2oyeWXgaCXC5OqxwMOQoJzW2r5MsxCVFRWc/38Bd8spVayAz5648r0hnhqRJ GU6ccZqO/IC9UbPn5Qz9B5Ws2RmwSoITXH+lO3GLMt+n7bTHRLphxr1QsRYjSY// BHNuM7EAXNXb0dAligpATX5GYoJM4PcYbJgkQyISmEJbfp+LVsmefgGV2OG3Lqic R1gW1RiO+43cuhZYOD1iv8WVJMVC9Bk5nXnxuXhOQw== =ZglO -----END PGP SIGNATURE----- ------------------------------------------------------------------------- The following was automatically added to this message by the list server: To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site: http://micronet.berkeley.edu Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet. This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.
