A New Day, An Old Bug: Linux At Risk from ‘glibc' Vulnerability
The bug has existed since 2008.
The vulnerability was first introduced in the 2008 release of glibc 2.9. According to Google, the bug allows for remote code execution. ZDNet and other outlets have reported that this open-source bug affects "a large number of Linux distributions, software and devices," because Linux applications rely on this library.
Google and Red Hat have released a patch for the vulnerability, which can be found here.
Google says that software using the getaddrinfo() library function are at risk.
The glibc DNS client side resolver is vulnerable to a stack-based buffer overflow when the getaddrinfo() library function is used. Software using this function may be exploited with attacker-controlled domain names, attacker-controlled DNS servers, or through a man-in-the-middle attack.
The ZDNet article quotes Johannes Ullrich, CTO of the SANS Internet Story Center, as saying that this issue affects most Linux users: "Pretty much any Linux system uses glibc, and getaddrinfo is typically used to resolve IP addresses. Which means Linux servers as well as workstations, are vulnerable unless it runs an old version of glibc (pre 2.9)."
Patch & A Prayer
The April 2015 issue of Waters was dedicated to cybersecurity issues. One topic examined was the challenges of patching systems and servers.
For the article, the CIO of an asset management firm with approximately $150 billion under management, took Waters through the organization's patching routine.
The firm goes through, usually, five to eight updates per month for desktops, and those go "reasonably well," according to the executive. It's on the server side that the greatest challenges lie. As an example, the CIO says that most asset managers have, on average, more than 1,000 Windows-based servers in their data centers. Every month they receive 10-15 patches that cover relevant vulnerabilities, specific to the firm.
From the feature:
"The problem is that any one of those patches could break your application," he says. "You have a trading system, it's got a Windows server in your datacenter, and when you apply a patch for that vulnerability, it could potentially break your system. So you absolutely must test them on the server side, first. It's very challenging because there are so many of them."
That's 10 to 15 patches applied to 1,000-plus servers: 15,000-plus separate repetitions that need to be tested and monitored. The IT team applies the patches to its development and test servers once a month. There, they are tested to make sure that all the interconnected pieces in the system aren't affected.
"You'll always be a little bit behind," the CIO says. "Arguably, the day it comes out you should probably apply it, but there's a lag between testing and deployment. The good news is that your datacenter tends to be internal and walled off from the rest of the world; it's less exposed. You probably couldn't do that with a web-based application."
And all of that is just on the server side, before you get the network firewall and vendor connections.
"The struggle that we always have is the attention between the development staff and the patching activity," the CIO said. "Developers want to be left alone, they don't want any problems, and this is something that potentially interferes with what they're doing. There's a certain amount of pressure to either do it less often, to not do it at all, or delay it."
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: http://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Emerging Technologies
This Week: Startup Skyfire launches payment network for AI agents; State Street; SteelEye and more
A summary of the latest financial technology news.
Waters Wavelength Podcast: Standard Chartered’s Brian O’Neill
Brian O’Neill from Standard Chartered joins the podcast to discuss cloud strategy, costs, and resiliency.
SS&C builds data mesh to unite acquired platforms
The vendor is using GenAI and APIs as part of the ongoing project.
Chevron’s absence leaves questions for elusive AI regulation in US
The US Supreme Court’s decision to overturn the Chevron deference presents unique considerations for potential AI rules.
Reading the bones: Citi, BNY, Morgan Stanley invest in AI, alt data, & private markets
Investment arms at large US banks are taken with emerging technologies such as generative AI, alternative and unstructured data, and private markets as they look to partner with, acquire, and invest in leading startups.
Startup helps buy-side firms retain ‘control’ over analytics
ExeQution Analytics provides a structured and flexible analytics framework based on the q programming language that can be integrated with kdb+ platforms.
The IMD Wrap: With Bloomberg’s headset app, you’ll never look at data the same way again
Max recently wrote about new developments being added to Bloomberg Pro for Vision. Today he gives a more personal perspective on the new technology.
LSEG unveils Workspace Teams, other products of Microsoft deal
The exchange revealed new developments in the ongoing Workspace/Teams collaboration as it works with Big Tech to improve trader workflows.