Re: GNU C Library: Multiple vulnerabilities
user49b <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <[email protected]> |
Hi Is there any update on this issue. Regards Christo ------------------------------------------------------------------------ *From:* Tapani Tarvainen <mailto:ipcop-IXVv/[email protected]> *Sent:* Saturday, March 26, 2016 11:50AM *To:* Ipcop-user <mailto:[email protected]> *Subject:* Re: [IPCop-user] GNU C Library: Multiple vulnerabilities > There's still been no glibc patch for IpCop, and I just noticed > there wasn't even a ticket open about this (I opened one now). > > This is getting a bit long in the tooth. I can't help wondering > if there's something in IpCop development process that makes > it difficult to do small patches quickly, or is there something > in this case that makes updating just glibc complicated. > > While I understand developers are busy volunteers, patching security > bugs fast is something I think a firewall distro should prioritize > rather high. > > -- > Tapani Tarvainen > > On Fri, Feb 19, 2016 at 07:44:46PM +0200, Tapani Tarvainen (ipcop-IXVv/[email protected]) wrote: > >> Yes it is, at least CVE-2015-7547. And it should be patched ASAP. >> >> As an interim band-aid, something like this in rc.firewall.local might help: >> >> iptables -A CUSTOMINPUT -p udp -m udp --dport 53 -m length --length 513:65535 -j DROP >> iptables -A CUSTOMINPUT -p tcp -m tcp --dport 53 -m length --length 1025:65535 -j DROP >> >> -- >> Tapani Tarvainen >> >> On Thu, Feb 18, 2016 at 07:21:47PM +0100, Dan Johansson ([email protected]) wrote: >> >>> Hi All, >>> >>> Does anyone here know if IPCop (2.1.9) is affected by these glibc >>> vulnerabilities: >>> >>> * The Google Security Team and Red Hat discovered a stack-based buffer >>> overflow in the send_dg() and send_vc() functions due to a buffer >>> mismanagement when getaddrinfo() is called with AF_UNSPEC >>> (CVE-2015-7547). >>> * The strftime() function access invalid memory when passed >>> out-of-range data, resulting in a crash (CVE-2015-8776). >>> * An integer overflow was found in the __hcreate_r() function >>> (CVE-2015-8778). >>> * Multiple unbounded stack allocations were found in the catopen() >>> function (CVE-2015-8779). >>> >>> Regards, >>> -- >>> Dan Johansson >>> *************************************************** >>> This message is printed on 100% recycled electrons! >>> *************************************************** > ------------------------------------------------------------------------------ > Transform Data into Opportunity. > Accelerate data analysis in your applications with > Intel Data Analytics Acceleration Library. > Click to learn more. > http://pubads.g.doubleclick.net/gampad/clk?id=278785351&iu=/4140 > _______________________________________________ > IPCop-user mailing list > [email protected] > Manage your subscription or unsubscribe > https://lists.sourceforge.net/lists/listinfo/ipcop-user > ------------------------------------------------------------------------------ What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic patterns at an interface-level. Reveals which users, apps, and protocols are consuming the most bandwidth. Provides multi-vendor support for NetFlow, J-Flow, sFlow and other flows. Make informed decisions using capacity planning reports. http://pubads.g.doubleclick.net/gampad/clk?id=1444514421&iu=/41014381 _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user