Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

RedHat has a fix for 6 and 7 now: https://rhn.redhat.com/errata/RHSA-2015-0092.html


Does anyone have any insight into when we'll see CentOS packages start hitting the mirrors?


Packages are ready, but if your mirror don't have them, use manual way: http://systemz.pl/post/fast-ghost-fix-for-cve-2015-0235/ It's for CentOS 6



They are now available, on CentOS 6.4 yum update glibc installs glibc-2.12-1.149.el6_6.5

changelog: * Mon Jan 19 2015 Siddhesh Poyarekar <siddhesh@redhat.com> - 2.12-1.149.5 - Fix parsing of numeric hosts in gethostbyname_r (CVE-2015-0235, #1183533).

Qualys GHOST program returns "not vulnerable" after the upgrade.


I just updated this on a CentOS 6 box, and it broke the server. After I rebooted, it never came online. Luckily it was a backup server, so it's not critical. Right now I'm just waiting for the customer to contact iweb to figure out what went wrong. This is a vanilla server with just some of my software installed (which couldn't possibly have prevented the server from rebooting).

Obviously there is some dependency that they forgot to add, so I would hold off on updating anything unless you don't really care if the server is offline for a while.


The problem was the iweb smart layer - they just needed to recreate the smart layer.


Apparently packages are built but currently awaiting signing + release. Hopefully within an hour or two they should hit the mirrors.


[deleted]


This is for https://rhn.redhat.com/errata/RHSA-2015-0016.html

This was related to iconv() and UTF8.

This is NOT the fix for this CVE.


That release seems to be dated 7 January 2015.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: