Re: [exim] CVE-2015-0235 - glibc gethostbyname remotelyexplo…

Page principale
Supprimer ce message
Répondre à ce message
Auteur: Roman Rybalko
Date:  
À: exim-users
Sujet: Re: [exim] CVE-2015-0235 - glibc gethostbyname remotelyexploitable via exim

>> Jumping ship would be doing something for the sake of doing something,
>> addressing only whichever API most recently happened to have a
>> vulnerability; it does not address any systemic issues and there's
>> no guarantee that it would actually help.
> It is in PHP too. Have, temporarily, disabled verify = helo and the PHP
> instances.

Note that vulnerable are only Server/Desktop Linux systems, i.e. that
use GNU libc library.
FreeBSD/Solaris/MacOS/etc., also embedded Linuxes with uClibc or custom
libc - all are OK.