Eight-Year-Old Vulnerability Exposes Thousands of Apps, Devices to Attack

Advertisement
By Manish Singh | Updated: 17 February 2016 18:14 IST

Researchers have discovered a critical vulnerability in the GNU C Library, glibc, which is exposing many Unix-based systems such as Linux servers to a range of security attacks. According to estimates, hundreds of thousands of devices, as well as apps utilising the GNU free software project are believed to be vulnerable. All versions of glibc starting with v2.9 are vulnerable. The patch has been made available and server admins are advised to update their system as soon as possible.

Google and Red Hat researchers said on Tuesday that they have independently found the vulnerability in the GNU C Library, a collection of open source codes that is utilised by many apps and hardware including IoT devices. The bug, which has been around since 2008, resides in a function called getaddrinfo(), which is designed to allow users to provide domain-name lookups.

The vulnerability can be exploited when an app or vulnerable device requests for some query such as translation of a Web address into its numerical IP address from a compromised domain name or server. The bug also allows an attacker to monitor and manipulate data passing between a compromised app or device to the Web. It can also allow an attacker to perform remote code execution. "No, seriously, patch glibc today," wrote security researcher Kenn White. "This is bad."

Advertisement

"[...] We were able determine that the issue could result in remote code execution," researchers at Google wrote in a blog post. "Our initial investigations showed that the issue affected all the versions of glibc since 2.9. You should definitely update if you are on an older version though. If the vulnerability is detected, machine owners may wish to take steps to mitigate the risk of an attack."

Advertisement

Computers running Windows, OS X, iOS or Android should not be affected. API Web services and other Web frameworks like PHP and Python, on the other hand, are affected. The patch for the bug is now available, and server admins are advised to install it on their machines right away.

The researchers at Google also took the opportunity to remind people that free-software projects don't always get patched in a timely manner. The bug was first reported to them last year. Users also should realise that modems and other devices can also become vulnerable, and should be handled carefully.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. Amazon Sale 2025: Check Top Deals on These iQOO Smartphones
  2. These Companies Fired Over 10K Employees Between July and September 2025
  3. Amazon Great Indian Festival Sale 2025: Check Early Deals on Tablets
  4. Nothing Ear 3 With 'Super Mic' Feature, Up to 45dB ANC Launched: See Price
  5. These Samsung Phones Will Get Price Drops Ahead of Festive Season
  6. DJI Mini 5 Pro With 1-Inch Camera Sensor Launched at This Price
  7. Xiaomi Announces Offers on These Products Ahead of Amazon, Flipkart Sales
  1. Astronomers Reveal Sudden Explosion of Small Asteroid Over France
  2. Rare ‘Crescent Sunrise’ Solar Eclipse to Grace Skies Over Antarctica and New Zealand
  3. Sun Shows Signs of Rising Activity Following Decades of Weakening, Study Finds
  4. IMAP Space Weather Mission to Lift Off Soon, NASA Confirms Broadcast Plans
  5. Microsoft's Xbox Full-Screen Experience Leaks on Other Windows Handhelds Ahead of ROG Xbox Ally Debut
  6. Cellecor Comet CBS-05 Pro Bluetooth Speaker Launched in India: Price, Features
  7. Samsung Galaxy S24 Ultra, Galaxy S24 FE, Galaxy A55 5G and More to Go on Sale With Discounts During Festive Season
  8. Coinbase Urges US DOJ Action as SEC Mulls Dropping Lawsuit Against Crypto Exchange
  9. Vivo V60 Lite 4G Design, Specifications Leaked; Tipped to Launch With Snapdragon 685 SoC, 6,500mAh Battery
  10. Nothing Ear 3 Launched With Super Mic Feature, Up to 45dB Active Noise Cancellation: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.