The GHOST in the Linux Machine? Busted | Internet News

The GHOST in the Linux Machine? Busted

Jan 29, 2015
1 minute read

There isn’t all the much reason to be afraid of GHOST (gethostbyname) CVE-2015-0235 vulnerability in the open-source Linux GNU C LIbary (glibc) – is there?

The GHOST vulnerability was publicly disclosed (http://www.openwall.com/lists/oss-security/2015/01/27/9) by security vendor Qualys on an open-source security mailing list on January 27. While the vulnerability dis

“During a code audit performed internally at Qualys, we discovered a buffer overflow in the __nss_hostname_digits_dots() function of the GNU C Library (glibc),” the advisory warns. “This bug is reachable both locally and remotely via the gethostbyname*() functions, so we decided to analyze it — and its impact — thoroughly, and named this vulnerability “GHOST”.

While Qualys’ disclosure about the vulnerability is new, and the flaw has shiny new CVE number too (CVE-2015-0235), by Qualys’ own admission the bug was fixed on August 12, 2013 in the glibc-2.18 update.

So what’s the problem?

Read the full story at eWEEK:
GHOST Bug Not New, but Can Haunt Older Linux Versions

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.