Eight-Year-Old Vulnerability Exposes Thousands of Apps, Devices to Attack

Advertisement
By Manish Singh | Updated: 17 February 2016 18:14 IST

Researchers have discovered a critical vulnerability in the GNU C Library, glibc, which is exposing many Unix-based systems such as Linux servers to a range of security attacks. According to estimates, hundreds of thousands of devices, as well as apps utilising the GNU free software project are believed to be vulnerable. All versions of glibc starting with v2.9 are vulnerable. The patch has been made available and server admins are advised to update their system as soon as possible.

Google and Red Hat researchers said on Tuesday that they have independently found the vulnerability in the GNU C Library, a collection of open source codes that is utilised by many apps and hardware including IoT devices. The bug, which has been around since 2008, resides in a function called getaddrinfo(), which is designed to allow users to provide domain-name lookups.

Advertisement

The vulnerability can be exploited when an app or vulnerable device requests for some query such as translation of a Web address into its numerical IP address from a compromised domain name or server. The bug also allows an attacker to monitor and manipulate data passing between a compromised app or device to the Web. It can also allow an attacker to perform remote code execution. "No, seriously, patch glibc today," wrote security researcher Kenn White. "This is bad."

"[...] We were able determine that the issue could result in remote code execution," researchers at Google wrote in a blog post. "Our initial investigations showed that the issue affected all the versions of glibc since 2.9. You should definitely update if you are on an older version though. If the vulnerability is detected, machine owners may wish to take steps to mitigate the risk of an attack."

Advertisement

Computers running Windows, OS X, iOS or Android should not be affected. API Web services and other Web frameworks like PHP and Python, on the other hand, are affected. The patch for the bug is now available, and server admins are advised to install it on their machines right away.

The researchers at Google also took the opportunity to remind people that free-software projects don't always get patched in a timely manner. The bug was first reported to them last year. Users also should realise that modems and other devices can also become vulnerable, and should be handled carefully.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Oppo Enco Air 5 Pro Review: Pure Value, No Compromises
  2. WhatsApp Now Lets You Reserve Your Username Before the Feature Goes Live
  3. Samsung Galaxy Z Flip 8, Fold 8 Ultra Might Launch With These Upgrades
  4. These Upcoming OnePlus Phones Could Arrive With 185Hz Displays for Gamers
  5. Nothing Says Its Upcoming Phone 4b Will Feature a Snapdragon Chip
  6. Moto Pad 70 Pro With a 10,200mAh Battery Debuts in India at This Price
  7. These iPhone Models Will Be Discounted During the Flipkart Sale
  8. Samsung Galaxy M47 5G Arrives With a 6,000mAh Battery: See Price in India
  9. This is When Apple Could Launch the iPhone 18 Pro and iPhone 18 Pro Max
  1. WhatsApp Now Lets You Reserve Your Username Before the Much-Anticipated Feature Goes Live
  2. Huawei Mate 90 Series Launch Timeline Revealed in New Leak; Mate XT 2 May Arrive Separately
  3. Xiaomi, Apple, Google Reportedly Join Hands to Advance Qi 50W Wireless Charging Standard
  4. Loopring Shuts Down Decentralised Exchange, Halts Trading Operations
  5. Kingdom Come: Deliverance 2 Has Sold 6 Million Copies, Warhorse Studios Confirms
  6. Sony Bravia 9 II, Bravia 7 II 4K RGB LED TVs Launched in India With XR Processor: Price, Features
  7. Nothing Phone 4b Confirmed to Feature Snapdragon Processor A Week Ahead of Debut
  8. Samsung Galaxy Z Flip 8 Tipped to Support Fast Charging, Galaxy Z Fold 8 Ultra Might Arrive With a Larger Battery
  9. iPhone 18, iPhone 18e and iPhone Air 2 Display Specifications Leaked; iPhone 19 Pro Said to Enter Testing
  10. Samsung Galaxy M47 5G Launched in India With 6,000mAh Battery, Snapdragon 6 Gen 3 SoC: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.