Ghost gethost attack
John R. Sowden
jsowden at americansentry.net
Sat Mar 28 03:35:04 UTC 2015
On 03/27/2015 08:16 PM, Brandon Vincent wrote:
> On Fri, Mar 27, 2015 at 8:10 PM, American Sentry Systems, Inc.
> <mail at americansentry.net> wrote:
>> I just read in a security tade journal about the "Ghost" attach. I seems
>> that it stems from the glibc library. I was surprised that not much was
>> mentioned about since the security concerns were announced in January, 2015.
>> It seems that Ubuntu 14.04 fixed the issue but 12.04 did not. Between that
>> I did not see clear documentation.
> GHOST has been patched in support Ubuntu versions, including 12.04.
>
> Can you post the output of: "dpkg -s eglibc"?
>
> You are looking for a version that is 2.15-0ubuntu10.10 or higher.
>
> Brandon Vincent
>
Here it is:
john at sentry10:~$ dpkg -s eglibc
dpkg-query: package 'eglibc' is not installed and no information is
available
Use dpkg --info (= dpkg-deb --info) to examine archive files,
and dpkg --contents (= dpkg-deb --contents) to list their contents.
I think the key here is that it was fixed back at 10.10, which is why it
is not being discussed. I think the author in the security alarm rag
was trying to create some revenue by issuing a FUD article. He
specifically mentioned that ubuntu was not fixed until 14.04.
Sorry for bring up a 5 year old problem,
John
More information about the ubuntu-users
mailing list