glibc bug: Amahi impacts?

mcinroy
Posts: 35
Joined: Wed Feb 03, 2016 11:51 am

glibc bug: Amahi impacts?

Postby mcinroy » Wed Feb 17, 2016 7:56 am

Hello.

Was reading this article this morning:
"Extremely severe bug leaves dizzying number of software and devices vulnerable | Ars Technica"
http://arstechnica.com/security/2016/02 ... ulnerable/

Was wondering if anyone else had read about it, or whether anyone could comment on how it impacts Amahi?

User avatar
cpg
Administrator
Posts: 2618
Joined: Wed Dec 03, 2008 7:40 am
Contact:

Re: glibc bug: Amahi impacts?

Postby cpg » Wed Feb 17, 2016 8:35 pm

Yes, we saw that article. Quite alarmist. If you read through it ... you can see that
... weaponized exploits that successfully execute malicious code are "possible, but not straightforward" ...
Which is a little less worrying. Since the result is a crash, it's not an immediate code execution risk. For now. It may become an issue later.

We do not advice our users to open up their HDA to the wild wild internet, so that makes it such that an attacker would have to have access to the local network to begin with.

For people that open up their ssh or VPN (or web server), this may become an attack vector, though that makes it quite a smaller attack surface.

All in all, it's something we have to watch for. We may release an update that forces a glibc update soon, just to be safe.

Thanks for the post. Keeps us on our toes! :D
My HDA: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz on MSI board, 8GB RAM, 1TBx2+3TBx1

mcinroy
Posts: 35
Joined: Wed Feb 03, 2016 11:51 am

Re: glibc bug: Amahi impacts?

Postby mcinroy » Thu Feb 18, 2016 9:17 am

Y... Quite alarmist.

... less worrying.

... smaller attack surface.
Yes, agreed 100% on all fronts.

I felt it probably wasn't a significant risk. Mainly wondered whether there might be something included in the next release of Amahi to address the issue. I expect Fedora will be patched. Having Amahi covered would be great, too.

(Would also be good to know which Amahi apps might be at risk. I guess that may be up to each developer...)

Thanks for your response!

User avatar
bigfoot65
Project Manager
Posts: 11924
Joined: Mon May 25, 2009 4:31 pm

Re: glibc bug: Amahi impacts?

Postby bigfoot65 » Thu Feb 18, 2016 11:01 am

If Fedora gets patched, then Amahi is covered. The exploit would come from the OS.
ßîgƒσστ65
Applications Manager

My HDA: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz on MSI board, 16GB RAM, 1TBx1+2TBx2+4TBx2

Who is online

Users browsing this forum: No registered users and 37 guests