A critical vulnerability has been discovered in the GNU C Library (glibc), leaving almost all Linux machines and thousands of apps open to hackers who could take complete control of them!

Simply clicking on a link or connecting to a server can result in remote code execution (RCE), allowing hackers to steal your credentials, spy on users, take control of your computer, and more. The vulnerability is similar to the one from recent years, called the GHOST vulnerability (CVE-2015-0235), which left countless machines exposed and vulnerable to remote code execution (RCE) attacks, thus constituting a huge Internet threat.
The GNU C Library (glibc) is a collection of open source code that powers thousands of applications and most Linux distributions, including those distributed on routers and other types of hardware.
https://www.secnews.gr/101442/mazar-bot-android-malware/See also: Mazar BOT|Android Malware Roots your device & deletes everything!
The recent flaw, designated as CVE-2015-7547, is a stack-based buffer overflow vulnerability in glibc's DNS client-side resolver, which is used to translate human-readable domain names, such as google.com, into network IP addresses.
The buffer overflow flaw is triggered when the getaddrinfo() library function that performs domain-name lookups is in use, allowing hackers to remotely execute malicious code.
[alert size=”alert-block” variation=”alert-error”]Click here to see the Proof-of-Concept (POC) exploit code [/alert]
Patch glibc Vulnerability
Google analysts, working with Red Hat security analysts, have released a patch to fix the flaw.
However, it is now up to the Linux OS community and manufacturers to introduce the patch to their affected software and devices as soon as possible.
For those running servers, fixing the issue will be a simple process of downloading and installing the patch update.
But for other users, fixing the problem may not be so easy. Applications affected by the glibc vulnerability will need to be rebuilt with the updated version – a process that will take time, as users of the affected applications must wait for updates to be made available by the developers.
https://www.secnews.gr/
For more information about the glibc flaw, you can read the Red Hat blog post.
