CVE-2015-7547: critical bug in libc

Kurt Jaeger lists at opsec.eu
Wed Feb 17 13:50:30 UTC 2016


Hi!

> The project that's vulnerable is called "glibc", not "libc". The BSDs
> don't use glibc, so the phrase "nothing to see here" applies. glibc
> isn't even available in FreeBSD's ports tree.
> 
> TL;DR: FreeBSD is not affected by CVE-2015-7547.

A short note on the www.freebsd.org website would probably be helpful,
as this case will produce a lot of noise.

-- 
pi at opsec.eu            +49 171 3101372                         4 years to go !


More information about the freebsd-current mailing list