Re: GNU C Library: Multiple vulnerabilities

user49b <[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <[email protected]>
Hi

Is there any update on this issue.

Regards
Christo


------------------------------------------------------------------------

*From:* Tapani Tarvainen <mailto:ipcop-IXVv/[email protected]>
*Sent:* Saturday, March 26, 2016 11:50AM
*To:* Ipcop-user <mailto:[email protected]>
*Subject:* Re: [IPCop-user] GNU C Library: Multiple vulnerabilities

> There's still been no glibc patch for IpCop, and I just noticed
> there wasn't even a ticket open about this (I opened one now).
>
> This is getting a bit long in the tooth. I can't help wondering
> if there's something in IpCop development process that makes
> it difficult to do small patches quickly, or is there something
> in this case that makes updating just glibc complicated.
>
> While I understand developers are busy volunteers, patching security
> bugs fast is something I think a firewall distro should prioritize
> rather high.
>
> --
> Tapani Tarvainen
>
> On Fri, Feb 19, 2016 at 07:44:46PM +0200, Tapani Tarvainen (ipcop-IXVv/[email protected]) wrote:
>
>> Yes it is, at least CVE-2015-7547. And it should be patched ASAP.
>>
>> As an interim band-aid, something like this in rc.firewall.local might help:
>>
>> iptables -A CUSTOMINPUT -p udp -m udp --dport 53 -m length --length 513:65535 -j DROP
>> iptables -A CUSTOMINPUT -p tcp -m tcp --dport 53 -m length --length 1025:65535 -j DROP
>>
>> -- 
>> Tapani Tarvainen
>>
>> On Thu, Feb 18, 2016 at 07:21:47PM +0100, Dan Johansson ([email protected]) wrote:
>>
>>> Hi All,
>>>
>>> Does anyone here know if IPCop (2.1.9) is affected by these glibc
>>> vulnerabilities:
>>>
>>> * The Google Security Team and Red Hat discovered a stack-based buffer
>>>    overflow in the send_dg() and send_vc() functions due to a buffer
>>>    mismanagement when getaddrinfo() is called with AF_UNSPEC
>>>    (CVE-2015-7547).
>>> * The strftime() function access invalid memory when passed
>>>    out-of-range data, resulting in a crash (CVE-2015-8776).
>>> * An integer overflow was found in the __hcreate_r() function
>>>    (CVE-2015-8778).
>>> * Multiple unbounded stack allocations were found in the catopen()
>>>    function (CVE-2015-8779).
>>>
>>> Regards,
>>> -- 
>>> Dan Johansson
>>> ***************************************************
>>> This message is printed on 100% recycled electrons!
>>> ***************************************************
> ------------------------------------------------------------------------------
> Transform Data into Opportunity.
> Accelerate data analysis in your applications with
> Intel Data Analytics Acceleration Library.
> Click to learn more.
> http://pubads.g.doubleclick.net/gampad/clk?id=278785351&iu=/4140
> _______________________________________________
> IPCop-user mailing list
> [email protected]
> Manage your subscription or unsubscribe
> https://lists.sourceforge.net/lists/listinfo/ipcop-user
>

------------------------------------------------------------------------------
What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic
patterns at an interface-level. Reveals which users, apps, and protocols are 
consuming the most bandwidth. Provides multi-vendor support for NetFlow, 
J-Flow, sFlow and other flows. Make informed decisions using capacity planning
reports. http://pubads.g.doubleclick.net/gampad/clk?id=1444514421&iu=/41014381
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.