Fixing Problems Like The Ghost Bug
Posted: 15 Feb 2015, 23:38
Any suggestions on how to quickly fix ghost bug (CVE-2015-0235) in Porteus?
Slackware has a newer /slackware/a/glibc-solibs-2.20-i486-2.txz package available.
Could it just be as simple as downloading the package and creating a new module?
glibc forms part of the core of any linux system. I am not sure how the system is built.
Would everything have to be recompiled?
Similar problems will happen more frequently in the future as more bugs in linux/FOSS packages are discovered and is more than likely to happen just after a new version of Porteus is released. IMO totally unreasonable to ask the Porteus team to put out new release each month.
This time the problem is with glibc, next time it might be with the kernel, bash or some other vital package.
Now for the more interesting question:
Would it be possible for someone to bring forward some ideas on how to fix these problems in the future so that users could fix/update their own systems?
Thanks
Ted
Slackware has a newer /slackware/a/glibc-solibs-2.20-i486-2.txz package available.
Could it just be as simple as downloading the package and creating a new module?
glibc forms part of the core of any linux system. I am not sure how the system is built.
Would everything have to be recompiled?
Similar problems will happen more frequently in the future as more bugs in linux/FOSS packages are discovered and is more than likely to happen just after a new version of Porteus is released. IMO totally unreasonable to ask the Porteus team to put out new release each month.
This time the problem is with glibc, next time it might be with the kernel, bash or some other vital package.
Now for the more interesting question:
Would it be possible for someone to bring forward some ideas on how to fix these problems in the future so that users could fix/update their own systems?
Thanks
Ted