Results 1 to 3 of 3

Thread: libc6 flaw worry

  1. #1
    Senior Member registered user
    Join Date
    May 2006
    Location
    Columbia, Maryland USA
    Posts
    1,631

    libc6 flaw worry

    .
    I expressed my concern about the following news item to Klaus K:
    http://www.eweek.com/security/linux-...libc-flaw.html

    His comment on this was the following:
    Me too, since all glibc >= 2.9 versions till today are affected, with
    the glibc on Knoppix being no exception.

    For exploiting the vulnerability, the attacker must own the directly
    queried DNS server (i.e. the users access point, or the ISPs DNS server)
    and send manipulated DNS replies from there, or be able to hijack TCP
    connections, and in most cases, programs will just crash on the
    getaddrinfo() library call, but code injection on the stack may be
    possible. Though an attack isn't really easy, it's a real possibility.

    The easy commandline method (for USB flash disk users) for fixing the
    problem, thanks to debian's quick reaction in the unstable branch, would be:

    sudo apt-get update ; sudo apt-get install -t unstable libc6
    which also updates libc6 dependencies.
    I did this on my Knoppix 7.6.1 LiveUSB, and it updated my libc6 to 2.21.0,
    and didn't take up much space on my reiserfs persistence.

    IMO, it may be wise to make this interim correction, since updating the
    whole 4Gb Knoppix iso might not happen right away.

  2. #2
    Senior Member registered user
    Join Date
    May 2006
    Location
    Columbia, Maryland USA
    Posts
    1,631
    Should read updated to libc6 2.21-9, not 2.21.0.
    Last edited by utu; 02-23-2016 at 01:33 AM.

  3. #3
    Senior Member registered user
    Join Date
    May 2006
    Location
    Columbia, Maryland USA
    Posts
    1,631

    A reminder, in case you are not using 7.7.0.

    Regarding libc6...

    http://www.linux-magazine.com/Issues/2016/187/Ask-Klaus

    You don't need to buy the article, just see the first post here.
    Last edited by utu; 05-13-2016 at 06:07 PM.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


OEM Dell 130W HA130PM130 DA130PM130 Laptop Power Adapter Charger 4.5mm 6TTY6 XPS picture

OEM Dell 130W HA130PM130 DA130PM130 Laptop Power Adapter Charger 4.5mm 6TTY6 XPS

$26.99



Dell OEM R730XD 12LFF 2SFF 2x E5-2690v4 28C 48gb H730 iDRAC ENT RJ-45 picture

Dell OEM R730XD 12LFF 2SFF 2x E5-2690v4 28C 48gb H730 iDRAC ENT RJ-45

$630.00



OEM 130W USB-C Type-C Charger for Dell XPS 15 9500 9570 9575 17 9700 DA130PM170 picture

OEM 130W USB-C Type-C Charger for Dell XPS 15 9500 9570 9575 17 9700 DA130PM170

$34.88



Dell OEM Original Latitude 5400 Chromebook Laptop Battery, 4-Cell 68Wh, 3HWPP picture

Dell OEM Original Latitude 5400 Chromebook Laptop Battery, 4-Cell 68Wh, 3HWPP

$43.99



NEW OEM Dell 65W 19.5V Charger AC Power Supply Adapter For LA65NM130 332-1831 picture

NEW OEM Dell 65W 19.5V Charger AC Power Supply Adapter For LA65NM130 332-1831

$12.99



OEM Dell 90W AC Adapter Charger OptiPlex 3040 7040 3060 7050 3070 3020 9020M picture

OEM Dell 90W AC Adapter Charger OptiPlex 3040 7040 3060 7050 3070 3020 9020M

$14.69



Genuine OEM Dell 130W AC Adapter Charger Brick Large Tip 19.5V 6.7A picture

Genuine OEM Dell 130W AC Adapter Charger Brick Large Tip 19.5V 6.7A

$4.97



OEM Dell Inspiron 11 13 14 15 17 3000 5000 7000 AC Adapter Charger 65W 4.5mm Tip picture

OEM Dell Inspiron 11 13 14 15 17 3000 5000 7000 AC Adapter Charger 65W 4.5mm Tip

$10.99



Genuine 45W Power Adapter Charger for Dell DA45NM140 0KXTTW 4.5*3.0mm OEM picture

Genuine 45W Power Adapter Charger for Dell DA45NM140 0KXTTW 4.5*3.0mm OEM

$16.99



DELL OEM AMD RADEON RX 6700 XT 12GB GDDR6 GPU Used picture

DELL OEM AMD RADEON RX 6700 XT 12GB GDDR6 GPU Used

$249.99