www.zeroshell.org Forum Index www.zeroshell.org
Linux Distribution for server and embedded devices
 
 SearchSearch  RegisterRegister  UsergroupsUsergroups 
 ProfileProfile  Log inLog in  Log in to check your private messagesPrivate Message 

Serious Vulnerability and new release

 
Post new topic   Reply to topic    www.zeroshell.org Forum Index -> ZeroShell
View previous topic :: View next topic  
Author Message
fulvio
Site Admin


Joined: 01 Nov 2006
Posts: 1072

PostPosted: Sun Feb 01, 2015 10:18 pm    Post subject: Serious Vulnerability and new release Reply with quote

Hi,

all Zeroshell releases up to the 3.3.1 include a GLIBC version of the libraries vulnerable to possible buffer overflow. The vulnerability, called GHOST, could allow remote code execution. For these reasons, it is recommended to upgrade to Zeroshell 3.3.2 which includes the latest version of GLIBC as well as various other fixes.

Regards
Fulvio


Last edited by fulvio on Sun Dec 13, 2015 5:21 am; edited 1 time in total
Back to top
View user's profile Send private message Send e-mail
Marcelo



Joined: 23 Jan 2010
Posts: 41

PostPosted: Sun Feb 01, 2015 10:22 pm    Post subject: Reply with quote

Hi Fulvio,

Could you please confirm 3.3.2 default kernel is 32bit as opposed to 64bit?

Thanks
Back to top
View user's profile Send private message
fulvio
Site Admin


Joined: 01 Nov 2006
Posts: 1072

PostPosted: Sun Feb 01, 2015 10:25 pm    Post subject: Reply with quote

By default Zeroshell 3.3.2 start with a 32-bit kernel that can be replaced with a 64-bit version.

Regards
Fulvio
Back to top
View user's profile Send private message Send e-mail
Marcelo



Joined: 23 Jan 2010
Posts: 41

PostPosted: Sun Feb 01, 2015 10:30 pm    Post subject: Reply with quote

Thanks!
Back to top
View user's profile Send private message
r1vver



Joined: 09 Apr 2010
Posts: 22

PostPosted: Tue Feb 03, 2015 7:40 am    Post subject: Re: Serious Vulnerability and new release Reply with quote

and no img.gz again Sad
Back to top
View user's profile Send private message
SpeedD408



Joined: 06 Dec 2010
Posts: 9
Location: Mission Viejo, CA

PostPosted: Tue Feb 03, 2015 4:25 pm    Post subject: Reply with quote

Looks like 3.3.2 has 3.14.31-ZS. Will there be a 3.14.31-64-ZS? or we we go back to 3.14.29-64-ZS?
Back to top
View user's profile Send private message
reaperz



Joined: 13 Apr 2012
Posts: 94

PostPosted: Mon Feb 09, 2015 12:09 pm    Post subject: Reply with quote

AS I understood, the older 3.14.31-64-ZS kernel is vulnerable to GHOST? Correct me if I am wrong.

Anyway, I did not dare to install 64-bit kernel after updating to 3.3.2.
Back to top
View user's profile Send private message
micampo



Joined: 24 Dec 2008
Posts: 61

PostPosted: Thu Jun 18, 2015 2:50 am    Post subject: Re: Serious Vulnerability and new release Reply with quote

can anyone talk about their experience with 64bit kernel? how do I install it? that version use? on that processor?
thanks
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    www.zeroshell.org Forum Index -> ZeroShell All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group