View previous topic :: View next topic |
Author |
Message |
ViMan n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 18 Jun 2002 Posts: 51
|
Posted: Thu Aug 08, 2002 9:04 pm Post subject: Security Problem in Gentoo :( |
|
|
A questions about the Security flaw that hit Windows, Macs, and Linux (see http://zdnet.com.com/2100-1105-948728.html). It says that "Several vendors of Unix and Unix-like operating systems, including Red Hat, Debian, FreeBSD, Sun and NetBSD said that their software was affected by the issue, and issued fixes." How does this security flaw affect Gentoo? And are these fixes/patches? Thanks for your time. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
rac Bodhisattva
![Bodhisattva Bodhisattva](/images/ranks/rank-bodhisattva.gif)
![](images/avatars/42db5dbb3e1c92424d747.jpg)
Joined: 30 May 2002 Posts: 6553 Location: Japanifornia
|
Posted: Thu Aug 08, 2002 9:18 pm Post subject: |
|
|
Moved to Networking & Security.
glibc 2.2.5-r6 contains a patch for the sunrpc overflow. _________________ For every higher wall, there is a taller ladder |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
ViMan n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 18 Jun 2002 Posts: 51
|
Posted: Thu Aug 08, 2002 9:29 pm Post subject: |
|
|
What's the easiest way to patch it? emerge -u glibc? Also, is there any chance that doing so will break anything (glibc)? Thanks for your time. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
rac Bodhisattva
![Bodhisattva Bodhisattva](/images/ranks/rank-bodhisattva.gif)
![](images/avatars/42db5dbb3e1c92424d747.jpg)
Joined: 30 May 2002 Posts: 6553 Location: Japanifornia
|
Posted: Thu Aug 08, 2002 9:41 pm Post subject: |
|
|
It looks to me like everything past -r5 is still masked, so you would need to comment out the ">=sys-libs/glibc-2.2.5-r6" line in /usr/portage/profiles/package.mask, and then "emerge -u glibc". Yes, you need to be careful, because problems with glibc can put your system in an unusable state. I do not know the exact reason why it is still masked, but, as with all masked packages, you probably shouldn't install them on critical systems, and it's probably a good idea to have a binary package as a backup in case you experience problems. _________________ For every higher wall, there is a taller ladder |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Xor Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/gallery/Zelda/Zelda_-_Link.jpg)
Joined: 07 Jul 2002 Posts: 144
|
Posted: Fri Aug 09, 2002 8:19 pm Post subject: |
|
|
I admit it.... I'm still a little byte confused about the topic in general. If gentoo will ever get a major update of the glibc... how will the procedure be? I mean, will the old glibc be "protected" till all application are linked to the new one? or does the current "cleaning feature or portage" remove the old one as soon as the new once is in place, and probably render the system unusable....
Thanks
xor |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|