This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

CVE-2015-7547 status/fix ?

Hello,


I would like to know the status of UTM 9 regarding the newly discovered bug in glibc CVE-2015-7547 (buffer overflow in getaddrinfo()). it looks like the current version is vulnerable and therefore will require a fix.

I don't think there is a workaround possible: the suggested ones all resolve around blocking UDP DNS packets larger than 512 bytes and I don't think that is possible in UTM.



This thread was automatically locked due to age.
Parents Reply Children
  • Yup: 2.11.3

    edit: I didn't actually expect Sophos to fix it that quickly. it takes longer to integrate a change and test it than this. I would really have some info about possible workaround, though. I'm not really worried about the flaw to be weaponised that soon either: you'd need to work around ASLR and (probably) NX pages to do it which should be tricky. But the potential for persistent downtime is there.