2015å¹´1æ27æ¥(ç¾å°æé) Qualysã¯glibc(GNU C Library)ã«èå¼±æ§ãçºè¦ããæ å ±ãå ¬éãã¾ãããããã§ã¯é¢é£æ å ±ãã¾ã¨ãã¾ãã(æ«å®ã¾ã¨ããªã®ã§ç²¾åº¦ä½ããç¶²ç¾ æ§ç¡ãã§ããã) (1) èå¼±æ§é¢é£æ å ± Qualysãå ¬éããèå¼±æ§æ å ± The GHOST Vulnerability Qualys Security Advisory CVE-2015-0235 注æåèµ· IPA (注æ) libc ã®èå¼±æ§å¯¾çã«ã¤ãã¦(CVE-2015-0235) èå¼±æ§ã®æ¦è¦ glibcã®__nss_hostname_digits_dots() ã«ãã¼ããããã¡ãªã¼ãã¼ããã¼ã®èå¼±æ§ã å½è©²é¢æ°ã¯glibcã®gethostbyname()ã¨gethostbyname2()ããå¼ã°ãã¦ããã ã¢ããªã±ã¼ã·ã§ã³ã«ãã£ã¦ã¯ãDoSãã¾ãã¯ãªã¢ã¼ãããä»»æã®ã³ã¼ããå®è¡å¯è½ã¨ãªãå¯è½æ§
{{#tags}}- {{label}}
{{/tags}}