An old GHOST rears its head again
A new vulnerability discovered this week can give hackers very easy access to Linux-based systems. So easy, in fact, that a hacker can gain full access to a Linux machine with a simple email message.
This new vulnerability, called GHOST, exploits a Linux function present since 2000 but never previously used this way. A fix for what was then a potential danger was released in 2013, but was not implemented in most well-known stable Linux distributions, including Debian 7 (Wheezy), Red Hat Enterprise Linux 6 and 7, CentOS 6 and 7, and Ubuntu 12.04. Systems still using these versions without the fix are therefore vulnerable, including mail servers, firewalls and application servers.
Technical background:
The critical vulnerability is in the Linux GNU C Library (glibc) and is known as GHOST (CVE-2015-0235). It stems from the 'gethostbyname' functions on Linux systems using glibc-2.2, released on 10 November 2000. A fix became available on 21 May 2013 for glibc-2.17 and glibc-2.18, but was not incorporated into later versions of many popular distributions. The problem is a buffer overflow in glibc that can be exploited both locally and remotely to access other parts of the system.
SECWATCH offers checks of Linux systems for this new and particularly dangerous vulnerability, helping resolve the situation before more serious problems arise. Among the tools we use is the cloud-based Qualys Vulnerability Management solution, which shows whether systems are vulnerable to GHOST and what measures are needed.
For organisations already subscribing to SECWATCH vulnerability management, this security scan is automatically included within the agreed intervals, supplemented by ad hoc CVE-specific audits.
Quick To-do List (Server Administrators)
- Check whether your system is vulnerable
- Validate the environment variables
- Check whether the system handles internet traffic (HTTP, HTTPS, SMTP and similar)
- Patch the systems as soon as possible
See the following for background information and guidance
But if you want to be truly sure attackers are not abusing the GHOST exploit and making off with your data, SECWATCH Vulnerability Management offers the better solution. It shows you exactly where the vulnerabilities are and how we can resolve them for you.
