Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Anyone know how reliable that test is? I've got a system reporting not vulnerable but I'm not sure what glibc it has.


glibc 2.18 and greater were already patched, but it wasn't recognized as an RCE vulnerability at the time. See the first bullet under the "Mitigating factors" section in the link.

You can check your libc version with:

  ldd --version


I've got a system reporting glibc 2.11, but the test reports 'not vulnerable'.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: