Results 1 to 2 of 2

Thread: About some security news on glibc.

  1. #1
    Join Date
    Sep 2006
    Location
    France.
    Beans
    Hidden!
    Distro
    Ubuntu Mate 16.04 Xenial Xerus

    About some security news on glibc.

    I'm not sure i get the whole picture though..
    This popped in my news feed : http://www.ibtimes.co.uk/google-red-...ternet-1545687
    I do not know the "International Business Times", maybe I should be ashamed regarding their awards on their "about page"..
    I searched a bit before posting the link here though, well...

    Anyway, they point at http://dankaminsky.com/2016/02/20/skeleton/, most of the stuff is above my head, there is a newer post : http://dankaminsky.com/2016/02/21/ghost/
    If you look for "DNS bug" you find stuff back from 2008 or something, and very few things from the recent days : https://googleonlinesecurity.blogspo...nfo-stack.html

    I'm surprised there are no more news in the usual things I read, so I'm not sure about what to think.
    | My old and mostly abandoned blog |
    Linux user #413984 ; Ubuntu user #178
    J'aime les fraises.
    Nighty night me lovelies!

    | Reinstalling Ubuntu ? Please check this bug first ! |
    | Using a ppa ? Please install ppa-purge from universe, you may need it should you want to revert packages back |
    | No support requests / username changes by PM, thanks. |
    [SIGPIC][/SIGPIC]

  2. #2
    Join Date
    Jun 2005
    Beans
    Hidden!

    Re: About some security news on glibc.

    Thanks bapoumba for the links..
    Well I guess this should be the only good for now..
    On the plus side, although there are millions of DNS caches across the internet, no researchers have yet to be able to get the glibc DNS bug to work through caches, and therefore, Kaminsky says that only "some networks are going to be vulnerable to some cache traversal attacks sometimes".
    However, he says that while this might not be an immediate problem, if this flaw is not patched soon, it could become a much bigger problem a year or two down the line.
    Some talk awhile back about the net being too secure?
    There’s a level of maturity that can be brought to the table, and I think should. There are a lot of unanswered questions about the scope of this flaw, and many others, that perhaps neither vendors nor volunteer researchers are in the best position to answer. We can do better building the secure platforms of the future. Let’s start here.
    This should get some folks worked up a bit!
    Last edited by QDR06VV9; February 25th, 2016 at 11:21 PM. Reason: Add Info

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •