Blog | G5 Cyber Security

Ghost in the Machine: Linux Zero-Day Vulnerability Discovered

On Tuesday, Jan. 27, a zero-day vulnerability (CVE-2015-0235) was disclosed in the Linux operating system that allows malicious code to be executed on servers that use the GNU C Library (glibc) functionality. Linux programs that contain glibc are also affected. The vulnerability can be exploited both locally and remotely by all the gethostbyname*() functions. Any protocol that allows or requires client to specify a host to be resolved via DNS is at risk.”]

Source: https://securityintelligence.com/ghost-in-the-machine-linux-zero-day-vulnerability-opens-door-for-attack/

Exit mobile version