Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-29 Thread Simon Banton
At 15:09 -0800 28/1/15, David C. Miller wrote: Although I hate Oracle with a fury, one good thing is that they put all the updates they rebuild for their RHEL clone in a publicly viewable site. I'm guessing they pay Redhat for extended support on end of life RHEL4 to get access to the source

Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-28 Thread Simon Banton
Hi, For reasons which are too tiresome to bore you all with, I have an obligation to look after a suite of legacy CentOS 4.x systems which cannot be migrated upwards. I note on https://access.redhat.com/articles/1332213 the following comment from a RHN person: We are currently working on

Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-28 Thread Valeri Galtsev
On Wed, January 28, 2015 5:09 pm, David C. Miller wrote: - Original Message - From: Simon Banton cen...@web.org.uk To: CentOS mailing list centos@centos.org Sent: Wednesday, January 28, 2015 6:10:34 AM Subject: Re: [CentOS] CVE-2015-0235 - glibc gethostbyname Hi, For reasons

Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-28 Thread David C. Miller
- Original Message - From: Simon Banton cen...@web.org.uk To: CentOS mailing list centos@centos.org Sent: Wednesday, January 28, 2015 6:10:34 AM Subject: Re: [CentOS] CVE-2015-0235 - glibc gethostbyname Hi, For reasons which are too tiresome to bore you all with, I have

Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-27 Thread Peter Lawler
On 28/01/15 04:47, Always Learning wrote: Saw this on the Exim List:- SNIP I use Exim on C5 and C6 - should I be worried about Exim on C6 ? upstream references: https://rhn.redhat.com/errata/RHSA-2015-0092.html https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-0235 Note that in the

Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-27 Thread Peter Lawler
On 28/01/15 06:58, Peter Lawler wrote: despite upstream not referencing their 5th edition in their notes. Apologies for replying to myself on the list. Upstream referenced the bug in their 5th edition via a link in their a BZ, that's how I missed it from their Security Advisory page:

Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-27 Thread Valeri Galtsev
On Tue, January 27, 2015 2:35 pm, Thomas Eriksson wrote: On 01/27/2015 12:22 PM, Valeri Galtsev wrote: On Tue, January 27, 2015 1:58 pm, Peter Lawler wrote: On 28/01/15 04:47, Always Learning wrote: Saw this on the Exim List:- SNIP I use Exim on C5 and C6 - should I be worried about

Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-27 Thread Cian Mc Govern
Packages are being built for CentOS 5, 6 7 at the moment: https://twitter.com/CentOS/status/560128242682966017 https://twitter.com/CentOS/status/560138182441070592 On 27 January 2015 at 20:22, Valeri Galtsev galt...@kicp.uchicago.edu wrote: On Tue, January 27, 2015 1:58 pm, Peter Lawler

Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-27 Thread Thomas Eriksson
On 01/27/2015 12:22 PM, Valeri Galtsev wrote: On Tue, January 27, 2015 1:58 pm, Peter Lawler wrote: On 28/01/15 04:47, Always Learning wrote: Saw this on the Exim List:- SNIP I use Exim on C5 and C6 - should I be worried about Exim on C6 ? upstream references:

Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-27 Thread Valeri Galtsev
On Tue, January 27, 2015 1:58 pm, Peter Lawler wrote: On 28/01/15 04:47, Always Learning wrote: Saw this on the Exim List:- SNIP I use Exim on C5 and C6 - should I be worried about Exim on C6 ? upstream references: https://rhn.redhat.com/errata/RHSA-2015-0092.html When I read this I

Re: [CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-27 Thread Peter Lawler
On 28/01/15 07:30, Cian Mc Govern wrote: Packages are being built for CentOS 5, 6 7 at the moment: https://twitter.com/CentOS/status/560128242682966017 https://twitter.com/CentOS/status/560138182441070592 Thanks Cian :) Pete. ___ CentOS mailing

[CentOS] CVE-2015-0235 - glibc gethostbyname

2015-01-27 Thread Always Learning
Saw this on the Exim List:- From: Tony Finch dot--a...@dotat.at Subject: [exim] CVE-2015-0235 - glibc gethostbyname remotely exploitable via exim Date: Tue, 27 Jan 2015 17:33:45 + The Exim mail server is exploitable remotely if configured to perform extra security checks on the HELO