5 ms·
Redhat (RHEL5 unaffected) - https://access.redhat.com/security/cve/cve-2015-7547 https://access.redhat.com/security/cve/cve-2015-7547 - https://access.redhat.c
by ptrincr 11y ago
Redhat (RHEL5 unaffected) - https://access.redhat.com/security/cve/cve-2015-7547 https://access.redhat.com/security/cve/cve-2015-7547 - https://access.redhat.com/articles/2161461 https://access.redhat.com/articles/2161461
RHEL6 - https://rhn.redhat.com/errata/RHSA-2016-0175.html https://rhn.redhat.com/errata/RHSA-2016-0175.html - update to glibc-2.12-1.166.el6_7.7.x86_64.rpm
RHEL7 - https://rhn.redhat.com/errata/RHSA-2016-0176.html https://rhn.redhat.com/errata/RHSA-2016-0176.html - update to glibc-2.17-106.el7_2.4.x86_64.rpm
Debian - https://security-tracker.debian.org/tracker/CVE-2015-7547 https://security-tracker.debian.org/tracker/CVE-2015-7547
Use "aptitude show libc6" - needs to be 2.19-18+deb8u3 (jessie), 2.21-8 (sid)
Ubuntu - http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-7547.html http://people.canonical.com/~ubuntu-security/cve/2015/CVE-20...
SUSE - https://www.suse.com/security/cve/CVE-2015-7547.html https://www.suse.com/security/cve/CVE-2015-7547.html
Interesting to note this tip:
While it is only necessary to ensure that all processes are not using
the old glibc anymore, it is recommended to reboot the machines after
applying the security upgrade.
From - https://lists.debian.org/debian-security-announce/2016/msg00051.html https://lists.debian.org/debian-security-announce/2016/msg00...
Therefore at the very least you will need to restart anything which depends on glibc. This should give you a list of packages:
lsof | grep libc | awk '{print $1}' | sort | uniq
- shaggy 11y agoThanks for these. Has anyone seen a link from/for CentOS yes?
- ptrincr 11y agoNot sure about Centos, can't find anything. Looks like someone has submitted a patch for Fedora - https://bodhi.fedoraproject.org/updates/FEDORA-2016-0f9e9a34ce https://bodhi.fedoraproject.org/updates/FEDORA-2016-0f9e9a34... I'm guessing Ubuntu will add something here once they get a fixed released - http://www.ubuntu.com/usn/ http://www.ubuntu.com/usn/ Should be able to see centos updates here, once they are released, for files glibc-2.12* with a 2016 timestamp - http://mirror.centos.org/centos/6/updates/x86_64/Packages/ http://mirror.centos.org/centos/6/updates/x86_64/Packages/ http://mirror.centos.org/centos/7/updates/x86_64/Packages/ http://mirror.centos.org/centos/7/updates/x86_64/Packages/
- alinspired 11y agocentos patch has been released at http://mirror.centos.org/centos/6/updates/ http://mirror.centos.org/centos/6/updates/ Note: it's likely not propagated to all mirrors yet
- bits 11y agoUbuntu - http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-7547.html http://people.canonical.com/~ubuntu-security/cve/2015/CVE-20...
- nisa 11y agoJust out of interest: How is this classified medium by Ubuntu? If someone manages to bypass ASLR this is a remote exploit on every SSH server running glibc out there? Or did I misunderstood something? Out of the box SSH seems to use getaddrinfo: reverse mapping checking getaddrinfo for <host> [<ip>] failed - POSSIBLE BREAK-IN ATTEMPT!
- ptrincr 11y agoCheers!
- collinmanderson 11y agoUbuntu Trusty 14.04 user here. Am I correct that there's no patch out yet?
- ptrincr 11y agoNot that I can see
- collinmanderson 11y agoThanks.
- tomputer 11y agoOn Debian there is also the tool checkrestart available, it is part of the debian-goodies package. This might be useful if a reboot is (currently) not possible. apt-get install debian-goodies Then you can run: checkrestart And it will list services which require a restart. For example: service sudo restart service ssh restart service cron restart service ... On Debian 8 (Jessie) i had to restart the systemd services as well: systemctl daemon-reexec systemctl restart systemd-journald systemctl restart systemd-logind
- korethr 11y agoGentoo https://bugs.gentoo.org/show_bug.cgi?id=CVE-2015-7547 https://bugs.gentoo.org/show_bug.cgi?id=CVE-2015-7547
- ptrincr 11y agoThanks! Can't edit the original post now, else I would throw it in there and credit you.
- pferde 11y agoDo I understand it correctly that Gentoo does not plan to push out a fix for this sooner than in 30 days?
- mark-wagner 11y agoNo, they were talking about marking glibc-2.22 as stable i.e., removing the tilde from the arches in the KEYWORDS of the ebuild. glibc-2.22-r2 was released at the same time as glibc-2.21-r2 and it contains the fix for this issue. The Changelog merely says "misc upstream fixes" but I verified the relevant changes are there. The GLSA is https://security.gentoo.org/glsa/201602-02 https://security.gentoo.org/glsa/201602-02