Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Security Problem in Gentoo :(
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
ViMan
n00b
n00b


Joined: 18 Jun 2002
Posts: 51

PostPosted: Thu Aug 08, 2002 9:04 pm    Post subject: Security Problem in Gentoo :( Reply with quote

A questions about the Security flaw that hit Windows, Macs, and Linux (see http://zdnet.com.com/2100-1105-948728.html). It says that "Several vendors of Unix and Unix-like operating systems, including Red Hat, Debian, FreeBSD, Sun and NetBSD said that their software was affected by the issue, and issued fixes." How does this security flaw affect Gentoo? And are these fixes/patches? Thanks for your time.
Back to top
View user's profile Send private message
rac
Bodhisattva
Bodhisattva


Joined: 30 May 2002
Posts: 6553
Location: Japanifornia

PostPosted: Thu Aug 08, 2002 9:18 pm    Post subject: Reply with quote

Moved to Networking & Security.

glibc 2.2.5-r6 contains a patch for the sunrpc overflow.
_________________
For every higher wall, there is a taller ladder
Back to top
View user's profile Send private message
ViMan
n00b
n00b


Joined: 18 Jun 2002
Posts: 51

PostPosted: Thu Aug 08, 2002 9:29 pm    Post subject: Reply with quote

What's the easiest way to patch it? emerge -u glibc? Also, is there any chance that doing so will break anything (glibc)? Thanks for your time.
Back to top
View user's profile Send private message
rac
Bodhisattva
Bodhisattva


Joined: 30 May 2002
Posts: 6553
Location: Japanifornia

PostPosted: Thu Aug 08, 2002 9:41 pm    Post subject: Reply with quote

It looks to me like everything past -r5 is still masked, so you would need to comment out the ">=sys-libs/glibc-2.2.5-r6" line in /usr/portage/profiles/package.mask, and then "emerge -u glibc". Yes, you need to be careful, because problems with glibc can put your system in an unusable state. I do not know the exact reason why it is still masked, but, as with all masked packages, you probably shouldn't install them on critical systems, and it's probably a good idea to have a binary package as a backup in case you experience problems.
_________________
For every higher wall, there is a taller ladder
Back to top
View user's profile Send private message
Xor
Tux's lil' helper
Tux's lil' helper


Joined: 07 Jul 2002
Posts: 144

PostPosted: Fri Aug 09, 2002 8:19 pm    Post subject: Reply with quote

I admit it.... I'm still a little byte confused about the topic in general. If gentoo will ever get a major update of the glibc... how will the procedure be? I mean, will the old glibc be "protected" till all application are linked to the new one? or does the current "cleaning feature or portage" remove the old one as soon as the new once is in place, and probably render the system unusable....

Thanks
xor
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum