Re: [Hampshire] Patch your Linux systems ("Ghost" vulnerabil…

Top Page

Reply to this message
Author: Gordon Scott
Date:  
To: Hampshire LUG Discussion List
Subject: Re: [Hampshire] Patch your Linux systems ("Ghost" vulnerability CVE-2015-0235)
On Wed, 2015-01-28 at 11:12 +0000, Imran Chaudhry wrote:
> Sounds like a pretty serious one, proof of concept involved an email
> sent to a Exim mail server to get a remote shell.
>
> http://www.theregister.co.uk/2015/01/27/glibc_ghost_vulnerability/
>


Oh dear.

Why Oh Why do people use strcpy() etc., rather than strncpy() etc.?

Never mind security, that just sensible defensive programming!

Sheesh!

G.


--
Please post to: Hampshire@???
Web Interface: https://mailman.lug.org.uk/mailman/listinfo/hampshire
LUG URL: http://www.hantslug.org.uk
--------------------------------------------------------------