Skip to content

Davey Winder

delivering award-winning technology journalism since 1991

  • home
  • about me
  • follow me on mastodon
  • privacy policy
  • Toggle search form
image of programming code through a lens

No need to panic over damp squib Linux glibc flaw

Posted on February 18, 2016February 18, 2016 By Davey Winder

Two Google staffers have posted details of a Linux glibc (GNU C Library) stack-based buffer overflow vulnerability that sounds nasty…

Earlier this week, Google Staff Security Engineer Fermin J. Serna and Technical Program Manager Kevin Stadmeyer posted details of a Linux glibc (GNU C Library) stack-based buffer overflow vulnerability (CVE-2015-7547). The pair explained how they were able to craft a fully working exploit just to make matters worse. If you have been reading some of the headlines that have appeared since this disclosure, you might be forgiven for thinking that this is a major security event with devastating consequences. Here at IT Security Thing we have seen it described as putting “Every Linux Machine in Danger” and being both “catastrophic” and a “Linux Superbug” for example. For sure this is a flaw that has been around for a while, in every version of glibc since 2.9, which was released way back in 2008. It really does, therefore, have the potential to impact upon thousands of Linux devices, no denying that.

It all sounds very nasty, despite the mitigation efforts and the availability of a patch. So why would anyone take issue here? Well, what is open to debate, and there has been plenty of it within the IT security community already, is whether it’s actually that dangerous in the real world at all.

Click here to read complete article

News Tags:Analysis, Exploit, Google, Linux, Programming, Vulnerability

Post navigation

Previous Post: Trust in digital services is low – but is that a good thing for security?
Next Post: Compromised: the Linux Mint with a hole in it

Related Articles

New Mass Gmail Rejections To Start April 2024, Google Says Gmail
Big Game Hackers Smash $1 Billion Ransomware Barrier Cybercrime
Yeah, But No, But Yeah: The Strange Tale Of 3 Million Hacked Toothbrushes Hacking
Google To Crack Down Against Spammers To Protect Gmail Users Gmail
New Google Report Warns Of ‘Real And Significant Threat’ To User Privacy Google
iPhone Under Attack: U.S. Government Issues 21 Days To Comply Warning Apple

Categories

Post Archive

Tags

0day Analysis Android Apple Apps breach bug bounty Business Chrome crime Cybercrime Data Protection Encryption Enterprise Google Government Hackers Hacking Health healthcare industry iOS IoT iPhone Malware Microsoft News NHS Opinion passwords Phishing Privacy ransomware Research Russia Samsung threat intelligence Twitter Update Vulnerabilites vulnerabilities Vulnerability Windows Windows 10 zero-day

Copyright © 2025 Davey Winder .

×
Cookies
We serve cookies. If you think that's ok, just click "Accept all". You can also choose what kind of cookies you want by clicking "Settings". Read our cookie policy
Settings Refuse all Accept all
Cookies
Choose what kind of cookies to accept. Your choice will be saved for one year. Read our cookie policy
  • Necessary
    These cookies are not optional. They are needed for the website to function.
  • Statistics
    In order for us to improve the website's functionality and structure, based on how the website is used.
  • Experience
    In order for our website to perform as well as possible during your visit. If you refuse these cookies, some functionality will disappear from the website.
  • Marketing
    By sharing your interests and behavior as you visit our site, you increase the chance of seeing personalized content and offers.
Save Refuse all Accept all
GDPR Cookie Policy