View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Technology
  2. Cybersecurity
January 29, 2015

GHOST bug haunts Linux users

The vulnerability could give remote access of the system to the hackers.

By CBR Staff Writer

Researchers of Cloud Security firm Qualys have discovered vulnerability in Linux GNU C Library (glibc) library which can be manipulated to gain remote access of the attacked system.

Glibc is also is an integral part of the Linux operating system without which Linux system will not function.

Researchers found out buffer overflow in the __nss_hostname_digits_dots() function of glibc , and hackers could trigger it both locally and remotely via all the gethostbyname*() functions; which led to the naming of the bug as dubbed, ‘GHOST’.

Hackers could gain partial or remote access allowing for arbitrary code execution.

Qualys said that to manage the risk users will need to apply a patch from Linux vendor, and the company claims that it has worked with Linux distribution vendors to create patches that are now available to users.

Qualys added: "According to our data once the vulnerability has reached its half-life we will release the exploit.

"Half-life is the time interval measuring a reduction of a vulnerability’s occurrence by half. Over time, this metric shows how successful efforts have been to eradicate vulnerability.

Content from our partners
Powering AI’s potential: turning promise into reality
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline

"A shorter half-life indicates faster remediation. Half-life was originally coined by Qualys in the Laws of Vulnerability."

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU