From unknown Mon Apr 27 19:08:23 2026
X-Loop: owner@bugs.x2go.org
Subject: Bug#778: [X2Go-Dev] Bug#778: affected by CVE 2015-0235: Stop using gethosbyname()
Reply-To: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>, 778@bugs.x2go.org
Resent-From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
Resent-To: x2go-dev@lists.x2go.org
Resent-CC: X2Go Developers <x2go-dev@lists.x2go.org>
X-Loop: owner@bugs.x2go.org
Resent-Date: Sun, 01 Feb 2015 21:35:02 +0000
Resent-Message-ID: <handler.778.B778.142282648330952@bugs.x2go.org>
Resent-Sender: owner@bugs.x2go.org
X-X2Go-PR-Message: followup 778
X-X2Go-PR-Package: nx-libs
X-X2Go-PR-Keywords: 
Received: via spool by 778-submit@bugs.x2go.org id=B778.142282648330952
          (code B ref 778); Sun, 01 Feb 2015 21:35:02 +0000
Received: (at 778) by bugs.x2go.org; 1 Feb 2015 21:34:43 +0000
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,URIBL_BLOCKED
	autolearn=ham version=3.3.2
Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id BCBA55E030
	for <778@bugs.x2go.org>; Sun,  1 Feb 2015 22:34:41 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [78.46.204.98])
	by freya.das-netzwerkteam.de (Postfix) with ESMTPS id 3DD81B63;
	Sun,  1 Feb 2015 22:34:41 +0100 (CET)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id F3DD43C051;
	Sun,  1 Feb 2015 22:34:40 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de
Received: from grimnir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id x9eYVPj0Tfz1; Sun,  1 Feb 2015 22:34:40 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPS id A812E3B994;
	Sun,  1 Feb 2015 22:34:40 +0100 (CET)
Received: from p5B3B8F07.dip0.t-ipconnect.de (p5B3B8F07.dip0.t-ipconnect.de
 [91.59.143.7]) by mail.das-netzwerkteam.de (Horde Framework) with HTTP; Sun,
 01 Feb 2015 21:34:40 +0000
Date: Sun, 01 Feb 2015 21:34:40 +0000
Message-ID: <20150201213440.Horde.1rG47LN-OXvFq60u1NEL7Q5@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: Nable <nable.maininbox@googlemail.com>
Cc: 778@bugs.x2go.org
References: <1422774281.1428.5.camel@Nokia-N900>
 <CALxOYEaUfq4rCifweufEwXSyxBtiKTaU20SpCdV3Co10BQ=tzQ@mail.gmail.com>
In-Reply-To: <CALxOYEaUfq4rCifweufEwXSyxBtiKTaU20SpCdV3Co10BQ=tzQ@mail.gmail.com>
User-Agent: Internet Messaging Program (IMP) H5 (6.2.2)
Accept-Language: en,de
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 91.59.143.7
X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:32.0) Gecko/20100101
 Firefox/32.0 Iceweasel/32.0
Content-Type: multipart/signed; boundary="=_nR1IeqU-fNHgqWIYEO6oPg8";
 protocol="application/pgp-signature"; micalg=pgp-sha1
MIME-Version: 1.0

This message is in MIME format and has been PGP signed.

--=_nR1IeqU-fNHgqWIYEO6oPg8
Content-Type: text/plain; charset=ISO-8859-1; format=flowed; DelSp=Yes
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On  So 01 Feb 2015 13:40:59 CET, Nable wrote:

> Hi, Mike!
>
> I'm looking at this and previous bug (#777) and can't stop wondering
> whether applications should really contain workarounds for bugs in
> system libraries. Isn't it better to just depend on newer version
> of library (that has fixes for currently known bugs)?
>
> There are a lot of older bugs in glibc (that are fixed in current
> version), does it mean that applications should be bloated with
> workarounds for such bugs just in order to work more safely on machines
> where users don't pay enough attention to updates?

That is a true way of reasoning...

However, gethostbyname is deprecated in glibc and not really IPv4/IPv6=20=
=20
compliant=20[1].

Mike

[1] http://beej.us/guide/bgnet/output/html/multipage/syscalls.html#getaddri=
nfo

--=20

DAS-NETZWERKTEAM
mike=20gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.x=
fb

--=_nR1IeqU-fNHgqWIYEO6oPg8
Content-Type: application/pgp-signature
Content-Description: Digitale PGP-Signatur
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAABAgAGBQJUzpvwAAoJEJr0azAldxsxxZkP/3pCKHxkkn4QhdDKzK+QlQTZ
8dnaEdD0OVhIi5iL9hoyv8i9mk7fdlm4OmeoZhmSU3CTOkUSNfCsSsshN2Dku2T8
zeZ9oK8nAd1FEPbqNbrNNKezHwzn9Gbqe3P/HcCUmXUmqpQe/t+GUINqQC/vyEr1
Sf4IM8l1aiPrCimrRSo7XM9l/YHWCcHcdw76SAamhu5M8OPFnMx4BaisW7PDAsWN
AhDLqS302MuHezDmyxHx/yrThD3vuRoc3TxD5Q6ulTyJicVV2UZe065qqopULDfX
wq+kRjkfTxKSm5goNMfx+wFCw0it9nt1huRWWbW43vznW9g9ZoGE2/lX6y9ekk/M
PNQDLeWlvypuhSNws/eGPDyqYiUqQ1m01ZReTFXLJY2IlhAxsTNABqm838svWZJG
7QpBIdMjSyKwi1MKbvmXSIWy3VMW4WxnznIcX3igtevwfTYW5S4EF0HiiIY7VqT2
MfoCBNlpVE/EBrMBz2K0M6T4HVaIMo2rcCGyK0ZyaYe1dTJJ8pQSg2237fnakdDh
UcuRyVZhbJRiupjYSMUEuBLvOQkkGQqnQ8/s9dsp4W8tqt0zdkyl7/xwG0MG0rnW
bnPPkVQZ1iqFE+FaO3yU/V5f6/JRThhb3MrTEm7hvTK2O98tJbo6hNVJJBUxyvdE
IDt/kxBKL60nPTUqUjeP
=zf3T
-----END PGP SIGNATURE-----

--=_nR1IeqU-fNHgqWIYEO6oPg8--
