oss-sec mailing list archives

the other glibc issue


From: Hanno Böck <hanno () hboeck de>
Date: Wed, 28 Jan 2015 12:22:00 +0100

Hi,

Not sure why solardesigner didn't post this himself, but he tweetet
yesterday:
glibc "getaddrinfo() writes DNS queries to random file descriptors
under high load" https://sourceware.org/bugzilla/show_bug.cgi?id=15946
… "Fixed in 2.20", reopened, CVE?

The corresponding bug title says most of it. It's supposed to be fixed
in glibc 2.20, however there is a comment saying it is not.

cu,
-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42

Attachment: _bin
Description: OpenPGP digital signature


Current thread: