[求助] 老大 1月27日發(fā)布的 Linux Glibc庫(kù)嚴(yán)重安全漏洞修復(fù)通知 如何操作。
本帖最后由 3g210 于 2015-1-30 17:20 編輯
老大,1月27日發(fā)布的這個(gè) Linux Glibc庫(kù)嚴(yán)重安全漏洞修復(fù)通知 如何操作?小白們搞不懂!
我的操作系統(tǒng)是
CentOS 6.3 64位,謝謝!
Linux Glibc庫(kù)嚴(yán)重安全漏洞修復(fù)通知
尊敬的阿里云ECS用戶:
您好,日前Linux GNU glibc標(biāo)準(zhǔn)庫(kù)的 gethostbyname函數(shù)爆出緩沖區(qū)溢出漏洞,漏洞編號(hào)為CVE-2015-0235。黑客可以通過(guò)gethostbyname系列函數(shù)實(shí)現(xiàn)遠(yuǎn)程代碼執(zhí)行,獲取服務(wù)器的控制權(quán)及Shell權(quán)限,此漏洞觸發(fā)途徑多,影響范圍大,請(qǐng)大家關(guān)注和及時(shí)臨時(shí)修復(fù),后續(xù)我們會(huì)盡快更新鏡像修復(fù)。請(qǐng)知曉。
一、 漏洞發(fā)布日期
2015年1月27日
二、 已確認(rèn)被成功利用的軟件及系統(tǒng)
Glibc 2.2到2.17 (包含2.2和2.17版本)
三、 漏洞描述
GNU glibc標(biāo)準(zhǔn)庫(kù)的gethostbyname 函數(shù)爆出緩沖區(qū)溢出漏洞,漏洞編號(hào):CVE-2015-0235。 Glibc 是提供系統(tǒng)調(diào)用和基本函數(shù)的 C 庫(kù),比如open, malloc, printf等等。所有動(dòng)態(tài)連接的程序都要用到Glibc。遠(yuǎn)程攻擊者可以利用這個(gè)漏洞執(zhí)行任意代碼并提升運(yùn)行應(yīng)用程序的用戶的權(quán)限。
http://ftp.riken.jp/pub/Linux/dag/redhat/el5/en/x86_64/rpmforge/repodata/primary.sqlite.bz2: (28, 'Operation too slow. Less than 1 bytes/sec transfered the last 30
seconds')
Trying other mirror.
rpmforge/primary_db | 7.0 MB 00:30
updates | 3.4 kB 00:00
updates/primary_db | 2.1 MB 00:03
Setting up Update Process
Resolving Dependencies
--> Running transaction check
---> Package glibc.x86_64 0:2.12-1.107.el6_4.2 will be updated
--> Processing Dependency: glibc = 2.12-1.107.el6_4.2 for package: glibc-devel-2.12-1.107.el6_4.2.x86_64
--> Processing Dependency: glibc = 2.12-1.107.el6_4.2 for package: nscd-2.12-1.107.el6_4.2.x86_64
--> Processing Dependency: glibc = 2.12-1.107.el6_4.2 for package: glibc-common-2.12-1.107.el6_4.2.x86_64
--> Processing Dependency: glibc = 2.12-1.107.el6_4.2 for package: glibc-headers-2.12-1.107.el6_4.2.x86_64
---> Package glibc.x86_64 0:2.12-1.149.el6_6.5 will be an update
--> Running transaction check
---> Package glibc-common.x86_64 0:2.12-1.107.el6_4.2 will be updated
---> Package glibc-common.x86_64 0:2.12-1.149.el6_6.5 will be an update
---> Package glibc-devel.x86_64 0:2.12-1.107.el6_4.2 will be updated
---> Package glibc-devel.x86_64 0:2.12-1.149.el6_6.5 will be an update
---> Package glibc-headers.x86_64 0:2.12-1.107.el6_4.2 will be updated
---> Package glibc-headers.x86_64 0:2.12-1.149.el6_6.5 will be an update
---> Package nscd.x86_64 0:2.12-1.107.el6_4.2 will be updated
---> Package nscd.x86_64 0:2.12-1.149.el6_6.5 will be an update
--> Finished Dependency Resolution
Dependencies Resolved
================================================================================
Package Arch Version Repository Size
================================================================================
Updating:
glibc x86_64 2.12-1.149.el6_6.5 updates 3.8 M
Updating for dependencies:
glibc-common x86_64 2.12-1.149.el6_6.5 updates 14 M
glibc-devel x86_64 2.12-1.149.el6_6.5 updates 983 k
glibc-headers x86_64 2.12-1.149.el6_6.5 updates 612 k
nscd x86_64 2.12-1.149.el6_6.5 updates 223 k