Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Another Linux (glibc) exploit  (Read 4125 times)

sevenlayermuddle

  • Helpful
  • Addicted Kitizen
  • *
  • Posts: 5369
Another Linux (glibc) exploit
« on: February 17, 2016, 07:05:58 PM »

As screamed by The Register..

http://www.theregister.co.uk/2016/02/16/glibc_linux_dns_vulernability/

Quote
Patch ASAP: Tons of Linux apps can be hijacked by evil DNS servers, man-in-the-middle miscreants

In fairness, I don't hold El Reg in high esteem these days, and I think their headline is probably alarming and misleading.

All the same, worth hoping for an update for any routers, Smart TVs etc, that might use embedded Linux.  'hoping' being the operative word.     ::)
Logged

burakkucat

  • Respected
  • Senior Kitizen
  • *
  • Posts: 38300
  • Over the Rainbow Bridge
    • The ELRepo Project
Re: Another Linux (glibc) exploit
« Reply #1 on: February 17, 2016, 07:14:45 PM »

That article appears to be rather "gutter-press" like and appears to be designed as "sensational" / "shock" / "horror", etc.

Unfortunately, they are rather behind the times with that report -- quite simply it is out of date stale news!  ::)
Logged
:cat:  100% Linux and, previously, Unix. Co-founder of the ELRepo Project.

Please consider making a donation to support the running of this site.

broadstairs

  • Kitizen
  • ****
  • Posts: 3700
Re: Another Linux (glibc) exploit
« Reply #2 on: February 17, 2016, 07:42:49 PM »

I seem to remember a patch for this in OpenSUSE ages ago....

Stuart
Logged
ISP:Vodafone Router:Vodafone Wi-Fi hub FTTP

ejs

  • Kitizen
  • ****
  • Posts: 2078
Re: Another Linux (glibc) exploit
« Reply #3 on: February 17, 2016, 07:46:36 PM »

Fedora got a glibc update for this today.

Also, most routers tend to use uClibc, which is smaller than glibc, and presumably won't have the exact same bugs, as it's a different project.
Logged

sevenlayermuddle

  • Helpful
  • Addicted Kitizen
  • *
  • Posts: 5369
Re: Another Linux (glibc) exploit
« Reply #4 on: February 17, 2016, 07:58:34 PM »

The Beeb covered it too, another organisation of which I have low opinion. :(

http://www.bbc.co.uk/news/technology-35592916

Quote
Glibc: Mega bug may hit thousands of devices

Interesting use of SI unit 'Mega' to create the splash-bang-wallop headline, then qualify the story describing affected devices with the mere word  'thousands'. :D

All the same, Beeb does link to the Google blog that announced the issue.  It was dated 16th Feb, so I suspect it is a new issue, despite resemblance to previous. 

https://googleonlinesecurity.blogspot.co.uk/2016/02/cve-2015-7547-glibc-getaddrinfo-stack.html
Logged

burakkucat

  • Respected
  • Senior Kitizen
  • *
  • Posts: 38300
  • Over the Rainbow Bridge
    • The ELRepo Project
Re: Another Linux (glibc) exploit
« Reply #5 on: February 17, 2016, 09:58:01 PM »

. . . the Google blog that announced the issue.  It was dated 16th Feb, so I suspect it is a new issue, despite resemblance to previous. 

https://googleonlinesecurity.blogspot.co.uk/2016/02/cve-2015-7547-glibc-getaddrinfo-stack.html

That is a public announcement by Google, the problem was discovered and essentially resolved before that date. As I commented earlier out-of-date, stale news!  ;)

It is best to consult the definitive listing for all CVEs -- at Mitre.
Logged
:cat:  100% Linux and, previously, Unix. Co-founder of the ELRepo Project.

Please consider making a donation to support the running of this site.

Chrysalis

  • Content Team
  • Addicted Kitizen
  • *
  • Posts: 7388
  • VM Gig1 - AAISP L2TP
Re: Another Linux (glibc) exploit
« Reply #6 on: February 17, 2016, 11:32:26 PM »

Fedora got a glibc update for this today.

Also, most routers tend to use uClibc, which is smaller than glibc, and presumably won't have the exact same bugs, as it's a different project.

dont talk about routers :( they a disaster waiting to happen, the vast majority of linux based routers I have used, use code that's circa 10 years old.
Logged
 

anything