Gentoo Archives: gentoo-user

From: Andrew Savchenko <bircoph@g.o>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Ghost cyber threat
Date: Thu, 29 Jan 2015 18:10:07
Message-Id: 20150129210953.c13713a81e454c2cf643f1a9@gentoo.org
In Reply to: Re: [gentoo-user] Ghost cyber threat by Grant
1 On Thu, 29 Jan 2015 08:52:57 -0800 Grant wrote:
2 > > Does anybody know more about this "security flaw in the open-source Linux
3 > > GNU C Library"
4 > >
5 > > http://www.theglobeandmail.com/technology/linux-makers-release-patch-to-thwart-new-ghost-cyber-threat/article22662060/?cmpid=rss1
6 >
7 >
8 > I updated a system of mine that was using an old version of glibc and
9 > rebooted. I can't do a full emerge world there or use various other
10 > portage tools due to the peculiarities of my current situation. Could
11 > I still be vulnerable?
12
13 Your system may be vulnerable to this issue only if you have
14 packages statically linked with vulnerable glibc libs, so most
15 likely — no. But your system may be affected by a plenty of other
16 issues in various packages.
17
18 At the very least you should apply all GLSAs to your system: while
19 they don't encompass all vulnerabilities, they should warn you
20 about most common and important ones.
21
22 Best regards,
23 Andrew Savchenko

Replies

Subject Author
Re: [gentoo-user] Ghost cyber threat Grant <emailgrant@×××××.com>