Showing posts with label Remote Code Execution Vulnerability. Show all posts
Showing posts with label Remote Code Execution Vulnerability. Show all posts

Thursday, 29 January 2015

Experts: Linux system Reboot After Installation GHOST Patch


Tuesday released a patch for a critical vulnerability in Linux, but after installing the system must be restarted, as experts warn. Through the GHOST vulnerability an attacker can take over vulnerable systems in certain cases. Still, the leak can not be compared with other major vulnerabilities as Heartbleed and Shellshock.

Most systems are not vulnerable because, says security expert Robert Graham . Modern software would use a different function and even software that uses the function which the leak can be invoked does so in a way that can not be abused."Even if software will use the vulnerable function is not to say that it is also vulnerable," the expert notes. Also, most systems would not be attacked by the leak and many of the exploits used only locally. Graham says that users also do not have to panic.

He gets applause Jen Ellis security company Rapid7. "Unlike a leak as Heartbleed is not always exploit the problem. The general consensus is that the bug is not easy to abuse," Ellis says. Until now, there would be only one known case that is easy to abuse. Both experts suggest that users of their systems after installing the patch have to reboot. Without a reboot services that will use the vulnerable library not be restarted.

Wednesday, 28 January 2015

Linux Systems Vulnerable To Criticism GHOST Leak



There is a critical vulnerability in Linux discovered which virtually all systems since 2000 at risk. Through the leak can take over a remote attacker without valid credentials vulnerable computers. The vulnerability is since November 2000 in the GNU C library.

The GNU C Library, also known as glibc, is an implementation of the standard C library and an important part of Linux.Without this library would be a Linux system does not work. The leak has researchers named GHOST received because it through the gethostbyname function is to call. An attacker could then execute arbitrary code on the system.



On May 21, 2013 between the releases of glibc 2.17 and glibc 2:18 there appeared a solution to the leak. However, the fix was not classified as a security advisory, making the most stable distributions with long-term support remained exposed, according to security firm Qualys discovered that the vulnerability. This is Debian 7 (wheezy), Red Hat Enterprise Linux 6 and 7 and Ubuntu 12.04.

"GHOST is a remote code execution risk, which makes it very easy for an attacker to compromise a machine. Example, an attacker can send a simple e-mail from a Linux system and automatically get full access to that machine," says Wolfgang Kandek, CTO at Qualys. Administrators and users are advised to install the updates now available from their supplier.