Impact of the GHOST vulnerability on TIBCO LogLogic appliances

Impact of the GHOST vulnerability on TIBCO LogLogic appliances

book

Article ID: KB0108212

calendar_today

Updated On:

Products Versions
TIBCO LogLogic Enterprise Virtual Appliance -
TIBCO LogLogic Security Event Manager -
TIBCO LogLogic Security Event Manager Enterprise Virtual Appliance -

Description

Description:

The GHOST (gethostbyname()heap overflow in glibc) vulnerability is a  recently announced serious weakness in the Linux glibc library. An attacker could use this weakness take control of your system remotely without any previous knowledge of system credentials.The Following TIBCO LogLogic products bundle and ship an affected version of the glibc library and therefore expose this vulnerability.

  • TIBCO LogLogic® Log Management Intelligence (all versions) on Linux
  • TIBCO LogLogic® Enterprise Virtual Appliance (all versions) on Linux
  • TIBCO LogLogic® Security Event Manager (all versions) on Linux
  • TIBCO LogLogic® Security Event Manager Enterprise Virtual Appliance (all versions) on Linux

We are in the process of building patches which we will make available to our customers as soon as we possibly can. Future releases of the appliances will come bundled with the updated libraries as well.  Watch for Late Breaking News (LBN) articles when the patches are ready for distribution.

Issue/Introduction

Impact of the GHOST vulnerability on TIBCO LogLogic appliances

Environment

TIBCO LogLogic®Log Management Intelligence (all versions) on Linux TIBCO LogLogic®Enterprise Virtual Appliance (all versions) on Linux TIBCO LogLogic®Security Event Manager (all versions) on Linux TIBCO LogLogic®Security Event Manager Enterprise Virtual Appliance (all versions) on Linux

Additional Information

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0235