Linux Security

Patching The Ghost Vulnerability

The Ghost vulnerability, also known as CVE-2015-0235, is an exploit in a library named glibc. This library is referenced by many applications which run on your server.

The exploit is a bug which affects 2 pieces of code which are used to do a DNS lookup, which translates a hostname to an IP address. A hacker could use a well-formed request to execute arbitrary code on your server.

Note: This only applies to self-managed Linux servers. This does not apply to any FreeBSD, or Windows server. This also does not apply to any server on our managed platform.

Luckily, this is a very simple fix and can be done in less than a minute.

Step 1: Update Packages

The glibc and nscd packages will need to be updated.

Please run the appropriate command based on your distribution of Linux. If your distribution is not listed, you can try both of these commands. One of them should work.

CentOS or RHEL:
yum -y update glibc nscd

 

Ubuntu, Gentoo, Debian:
sudo apt-get update glibc nscd

Step 2: Reboot

The only way to be absolutely sure that the vulnerable package is completely removed from your system is to reboot. There are many applications that could be running that will still have the old version of the library loaded. Theoretically you could restart all of these services, however it would be quicker, easier, and safer to reboot your system at a time when your server is not under heavy load.

shutdown -r now

Related Articles

  • How to clear the YUM cache?

    What is yum? The Yellowdog Updater, Modified (yum) is an open-source command-line package-management utility for Linux operating systems using the RPM Package Manager. Yum allows automatic updates, package and dependency...
  • Identifying malicious mail scripts on FreeBSD

    This article will help you identify an possible spam scripts that may be causing unwanted outbound mail which could cause your servers ip address to be blacklisted.There are many different...
  • Disk Benchmarking Tools.

    One of the main bottlenecks in server slowness is the Disk IO. If the speed of your disks are slow, then the CPUs of your servers may be wasting their CPU...
  • What is an Account Passphrase?

      Webair offers an extra layer of security to our clients when calling in regarding support called an Account Passphrase. This will be asked when calling into our phone support...