CVE-2015-0235対応

下書きだけ書いて放置してた。

glibc脆弱性 (通称:GHOST)の対応です。

特殊な手順とかはなく

$ sudo yum update glibc

これだけですね その後reboot

せっかくなのでansibleで実行した時のログでも貼っておきます。

[astel@astail.net] $ ansible -K -i provisioning/inventory/astel -u astel -m shell -a "sudo yum update glibc -y" sakura-server --sudo
sudo password: 
172.1.1.1 | success | rc=0 >>
Loaded plugins: aliases, changelog, downloadonly, fastestmirror, kabi, presto,
              : security, tmprepo, verify, versionlock
Loading support for CentOS kernel ABI
Loading mirror speeds from cached hostfile
 * base: www.ftp.ne.jp
 * epel: ftp.kddilabs.jp
 * extras: www.ftp.ne.jp
 * updates: www.ftp.ne.jp
Setting up Update Process
Resolving Dependencies
--> Running transaction check
---> Package glibc.x86_64 0:2.12-1.132.el6_5.4 will be updated
--> Processing Dependency: glibc = 2.12-1.132.el6_5.4 for package: glibc-headers-2.12-1.132.el6_5.4.x86_64
--> Processing Dependency: glibc = 2.12-1.132.el6_5.4 for package: glibc-devel-2.12-1.132.el6_5.4.x86_64
--> Processing Dependency: glibc = 2.12-1.132.el6_5.4 for package: glibc-common-2.12-1.132.el6_5.4.x86_64
---> Package glibc.x86_64 0:2.12-1.149.el6_6.5 will be an update
--> Running transaction check
---> Package glibc-common.x86_64 0:2.12-1.132.el6_5.4 will be updated
---> Package glibc-common.x86_64 0:2.12-1.149.el6_6.5 will be an update
---> Package glibc-devel.x86_64 0:2.12-1.132.el6_5.4 will be updated
---> Package glibc-devel.x86_64 0:2.12-1.149.el6_6.5 will be an update
---> Package glibc-headers.x86_64 0:2.12-1.132.el6_5.4 will be updated
---> Package glibc-headers.x86_64 0:2.12-1.149.el6_6.5 will be an update
--> Finished Dependency Resolution

Dependencies Resolved

================================================================================
 Package             Arch         Version                   Repository     Size
================================================================================
Updating:
 glibc               x86_64       2.12-1.149.el6_6.5        updates       3.8 M
Updating for dependencies:
 glibc-common        x86_64       2.12-1.149.el6_6.5        updates        14 M
 glibc-devel         x86_64       2.12-1.149.el6_6.5        updates       983 k
 glibc-headers       x86_64       2.12-1.149.el6_6.5        updates       612 k

Transaction Summary
================================================================================
Upgrade       4 Package(s)

Total download size: 20 M
Downloading Packages:
Setting up and reading Presto delta metadata
Processing delta metadata
Download delta size: 1.2 M
Presto reduced the update size by 78% (from 5.4 M to 1.2 M).
Package(s) data still to download: 14 M
Running rpm_check_debug
Running Transaction Test
Transaction Test Succeeded
Running Transaction
  Updating   : glibc-2.12-1.149.el6_6.5.x86_64                              1/8 
  Updating   : glibc-common-2.12-1.149.el6_6.5.x86_64                       2/8 
  Updating   : glibc-headers-2.12-1.149.el6_6.5.x86_64                      3/8 
  Updating   : glibc-devel-2.12-1.149.el6_6.5.x86_64                        4/8 
  Cleanup    : glibc-devel-2.12-1.132.el6_5.4.x86_64                        5/8 
  Cleanup    : glibc-headers-2.12-1.132.el6_5.4.x86_64                      6/8 
  Cleanup    : glibc-2.12-1.132.el6_5.4.x86_64                              7/8 
  Cleanup    : glibc-common-2.12-1.132.el6_5.4.x86_64                       8/8 
  Verifying  : glibc-common-2.12-1.149.el6_6.5.x86_64                       1/8 
  Verifying  : glibc-devel-2.12-1.149.el6_6.5.x86_64                        2/8 
  Verifying  : glibc-headers-2.12-1.149.el6_6.5.x86_64                      3/8 
  Verifying  : glibc-2.12-1.149.el6_6.5.x86_64                              4/8 
  Verifying  : glibc-2.12-1.132.el6_5.4.x86_64                              5/8 
  Verifying  : glibc-devel-2.12-1.132.el6_5.4.x86_64                        6/8 
  Verifying  : glibc-common-2.12-1.132.el6_5.4.x86_64                       7/8 
  Verifying  : glibc-headers-2.12-1.132.el6_5.4.x86_64                      8/8 

Updated:
  glibc.x86_64 0:2.12-1.149.el6_6.5                                             

Dependency Updated:
  glibc-common.x86_64 0:2.12-1.149.el6_6.5                                      
  glibc-devel.x86_64 0:2.12-1.149.el6_6.5                                       
  glibc-headers.x86_64 0:2.12-1.149.el6_6.5                                     

Complete!

でrebootして終わりです。