HomeSecurityCritical glibc Flaw puts Linux at risk! Fix it immediately!

Critical glibc Flaw Puts Linux at Risk! Fix It Immediately!

A critical vulnerability has been discovered in the GNU C Library (glibc), leaving almost all Linux machines and thousands of apps open to hackers who could take complete control of them! 

Critical glibc Flaw Puts Linux at Risk! Fix It Immediately!

Simply clicking on a link or connecting to a server can result in remote code execution (RCE), allowing hackers to steal your credentials, spy on users, take control of your computer, and more. The vulnerability is similar to the one from recent years, called the GHOST vulnerability (CVE-2015-0235), which left countless machines exposed and vulnerable to remote code execution (RCE) attacks, thus constituting a huge Internet threat.

The GNU C Library (glibc) is a collection of open source code that powers thousands of applications and most Linux distributions, including those distributed on routers and other types of hardware.

https://www.secnews.gr/101442/mazar-bot-android-malware/See also: Mazar BOT|Android Malware Roots your device & deletes everything!

The recent flaw, designated as CVE-2015-7547, is a stack-based buffer overflow vulnerability in glibc's DNS client-side resolver, which is used to translate human-readable domain names, such as google.com, into network IP addresses.

The buffer overflow flaw is triggered when the getaddrinfo() library function that performs domain-name lookups is in use, allowing hackers to remotely execute malicious code.

[alert size=”alert-block” variation=”alert-error”]Click here to see the Proof-of-Concept (POC) exploit code [/alert]

Patch glibc Vulnerability

Google analysts, working with Red Hat security analysts, have released a patch to fix the flaw.

However, it is now up to the Linux OS community and manufacturers to introduce the patch to their affected software and devices as soon as possible.

For those running servers, fixing the issue will be a simple process of downloading and installing the patch update.

But for other users, fixing the problem may not be so easy. Applications affected by the glibc vulnerability will need to be rebuilt with the updated version – a process that will take time, as users of the affected applications must wait for updates to be made available by the developers.

https://www.secnews.gr/100610/ethihak-security/btn-large” variation=”btn-success”]The first EthiHak live Contest is an EVENT!!!!! Infocom 2016 – EthiHak Contest – Register TODAY!

 In the meantime, you can help prevent exploitation of the flaw, if you are unable to immediately fix the glibc bug, by limiting all TCP DNS replies to 1024 bytes, and UDP DNS packets larger than 512 bytes.

For more information about the glibc flaw, you can read the Red Hat blog post.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS