TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Not So Spooky: Linux “Ghost” Vulnerability

38 pointsby matsuuover 10 years ago

3 comments

gtrubetskoyover 10 years ago
This article is misleading.<p>&quot;First of all, this vulnerability has long been patched&quot; - not true, it wasn&#x27;t patched on RedHat and Debian until yesterday.<p>&quot;many apps are not at risk&quot; - so, what, nothing to worry about?<p>&quot;the functions that are the subject of this vulnerability are obsolete&quot; - obsolete they may be, but a ton of software still uses them.<p>&quot;Taken together, the risk of actual exploits targeting GHOST is relatively small compared to other vulnerabilities like Shellshock or Heartbleed.&quot; - just because it is not widely known how to exploit this does not imply the risk is small. Let&#x27;s wait until someone figures this out or the POC exploit is made public.
评论 #8960898 未加载
评论 #8960756 未加载
评论 #8961570 未加载
hellbantestover 10 years ago
The fact that the patch has been out since May 2013 doesn&#x27;t help if few systems have it installed.<p>Qualys has developed a PoC that runs arbitrary code against a sample target.
gaiusover 10 years ago
These days you get a scary name and a logo, and <i>then</i> you find a bug to go with it...