GHOST Vulnerability…Not That Scary

If you have any questions, please contact SecurityMetrics support, 801.705.5700.

Updated:  
December 7, 2022
Cybersecurity
PCI
GDPR
GHOST Vulnerability…Not That Scary

Quick Answer: How Serious Is the GHOST Vulnerability (CVE-2015-0235)


GHOST is a Linux glibc buffer overflow vulnerability rated 10/10 by NIST, but extremely difficult to exploit, with only Exim Mail Transfer Agent confirmed possibly vulnerable.

  • GHOST affects gethostbyname and gethostbyname2 functions in glibc versions 2.2-2.18, patched since May 2013.
  • Affected systems included Debian 7, Red Hat Enterprise Linux 5/6/7, CentOS 6/7, and Ubuntu 12.04.
  • Only 0.01% of SecurityMetrics customer scans in 2015 detected Exim, and its vulnerable configuration is off by default.
  • Apply glibc patches if needed, and monitor logs for abnormal program terminations if concerned about a breach.

Who it affects, how hackers could use it, and what you should do about it.

The recently discovered GHOST vulnerability is a bug that could potentially allow a buffer overflow in Linux systems. Sounds scary, right? In reality, all the media surrounding this vulnerability has hyped it up more than it deserves.

Although GHOST (CVE-2015-0235) is categorized as a 10 on the NIST database, if you dive deeper into the vulnerability it has a very low probability and is extremely difficult to exploit.

Here are the facts

  • GHOST affects the gethostbyname and gethostbyname2 functions in the Linux GNU C library (glibc)
  • The vulnerability could enable attackers to remotely take control of a system through a buffer overflow
  • This vulnerability has been patched since May 2013, which means new Linux systems, and any patched systems, aren’t affected

Which systems are affected?

  • Debian 7 (Wheezy)
  • Red Hat Enterprise Linux 5/6/7
  • CentOS 6/7
  • Ubuntu 12.04
  • Any other systems using glibc versions from 2.2 to 2.18

See also: SSL 3.0 POODLE Vulnerability Update

Can I be compromised through GHOST?

While this is a legitimate attack, the likelihood of being compromised via GHOST is extremely small. So far, only the Exim Mail Transfer Agent has been confirmed as possibly exploitable. Even if you use Exim, the Exim gethostbyname configuration option is off by default.

Let us put this in context. Out of all the vulnerability scans SecurityMetrics customers ran on their systems in 2015, only .01% detected the use of Exim. That percentage decreases exponentially when you consider that the Exim gethostbyname configuration must be turned on for the Linux system to be vulnerable, and there must be an exploitable version of the glibc library on the system.

Our recommendations

  • Don’t panic
  • Apply glibc patches on your systems, if needed
  • If you’re worried about a breach, start watching your logs for abnormal program terminations (crash reports)
If you have any questions, please contact SecurityMetrics support, 801.705.5700.