Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][tlug] Chasing the GHOST in my machine
- Date: Fri, 30 Jan 2015 08:31:36 +0900
- From: CL <az.4tlug@example.com>
- Subject: [tlug] Chasing the GHOST in my machine
- User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Icedove/31.4.0
By now everyone has probably seen the GHOST security hole report? Well, here, or some other place on The Web?http://www.zdnet.com/article/critical-linux-security-hole-found/?tag=nl.e589&s_cid=e589&ttag=e589&ftag=TREc64629fAccording to the article, my Debian Wheezy (v.7.8) is vulnerable, but it provided a link to the bug reporthttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776391in which the author is told the issue is fixed. However, the "fix" seems to depend on a version number and I can't tell whether my version, which has now appeared on the "marked fixed" list is _really_ repaired, or not. I changed my preferences for all from "stable" to "wheezy backports" as I thought I'd read that the latter were applied sooner. A new version of libc6 _did_ appear to be downloaded and installed, but I want to be sure this isn't wishful thinking.In Debian, can patched and unpatched versions appear under the same version number? Is there a simple way to tell whether I have the patched version or still need to do something more (like download and run 2.19 from a Sid repository)?Output: # dpkg -l libc6 Desired=Unknown/Install/Remove/Purge/Hold| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description +++-===========================-==================-==================-============================================================ii libc6:amd64 2.13-38+deb7u7 amd64 Embedded GNU C Library: Shared libraries ii libc6:i386 2.13-38+deb7u7 i386 Embedded GNU C Library: Shared libraries... and 2.13-38+deb7u7 is now reported to be "patched" It's a bitch when you know just enough to break everything and fix nothing. -- CL
- Follow-Ups:
- Re: [tlug] Chasing the GHOST in my machine
- From: Nicolas Limare
- Re: [tlug] Chasing the GHOST in my machine
- From: Jens Oliver John
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Participating fosdem?
- Next by Date: Re: [tlug] Chasing the GHOST in my machine
- Previous by thread: Re: [tlug] Participating fosdem?
- Next by thread: Re: [tlug] Chasing the GHOST in my machine
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links