Bug 7258

Summary: glibc: __nss_hostname_digits_dots() heap-based buffer overflow (CVE-2015-0235)
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Sona Sarmadi <sona.sarmadi>
Component: coreAssignee: Saul Wold <sgw>
Status: RESOLVED FIXED QA Contact:
Severity: critical    
Priority: Undecided CC: meta.mr.watcher, meta.watcher
Version: unspecified   
Target Milestone: ---   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Sona Sarmadi 2015-01-28 07:13:24 UTC
A heap overflow in glibc's gethostbyname() function.

This is redhat's report:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-0235


Upstream patch:

https://sourceware.org/git/?p=glibc.git;a=commit;h=d5dd6189d506068ed11c8bfa1e1e9bffde04decd


This seems to be a reported from qualys, here is "Qualys Security Advisory CVE-2015-0235 - GHOST: glibc gethostbyname"

http://www.openwall.com/lists/oss-security/2015/01/27/9
Comment 1 Sona Sarmadi 2015-01-28 12:13:06 UTC
From yocto mailing list:

> On 28 January 2015 at 11:17, Damian, Alexandru 
> <alexandru.damian@intel.com>
> wrote:
> > Do we need to open a bug to track this ?
> 
> Probably for the best to ensure it goes into all the branches we support.

FYI, none of the branches we still officially support use (e)glibc older than 2.18, which is where the fix went in upstream; even dora that just went out of support has 2.18 as the default (2.17 is included though).

Cheers,
Paul

Closing this issue now since this does not affects us!!