考虑到CVE-2015-0235,我今天开始升级Ubuntu服务器。我有一个12.04.5LTS服务器,它拒绝将我的libc6包更新到不包含该漏洞的版本(2.15-0ubuntu10.10,根据这)。当我运行apt-get update && apt-get upgrade和apt-get dist-upgrade时,libc6被升级到2.15-0ubuntu10.9版本,而不是2.15-0ubuntu10.10版本。更新包之后,我重新启动了服务器。
然后我运行在安全咨询中找到的C程序,查看服务器是否仍然易受攻击,因为输出是“易受攻击的”。
我的/etc/apt/sources.list文件包括Ubuntu精确的安全存储库:
deb http://security.ubuntu.com/ubuntu precise-security main restricted
deb-src http://security.ubuntu.com/ubuntu precise-security main restricted
deb http://security.ubuntu.com/ubuntu precise-security universe
deb-src http://security.ubuntu.com/ubuntu precise-security universe
deb http://security.ubuntu.com/ubuntu precise-security multiverse
deb-src http://security.ubuntu.com/ubuntu precise-security multiverse为什么我不能将libc6更新为2.15-0ubuntu10.10?
编辑:我刚刚尝试安装@geoffmcc链接的.deb,将dpkg -i libc6_2.15-0ubuntu10_amd64.deb作为根用户运行,下面是我得到的错误消息:
dpkg: warning: downgrading libc6 from 2.15-0ubuntu10.9 to 2.15-0ubuntu10.
(Reading database ... 102787 files and directories currently installed.)
Preparing to replace libc6 2.15-0ubuntu10.9 (using libc6_2.15-0ubuntu10_amd64.deb) ...
Unpacking replacement libc6 ...
dpkg: dependency problems prevent configuration of libc6:
libc6 depends on libc-bin (= 2.15-0ubuntu10); however:
Version of libc-bin on system is 2.15-0ubuntu10.9.
dpkg: error processing libc6 (--install):
dependency problems - leaving unconfigured
Errors were encountered while processing:
libc6编辑2:我不知道为什么,但是今天早上再次运行apt-get update && apt-get upgrade提供了我需要的更新。我现在可以运行C漏洞检查器,并获得“不容易受攻击”的输出。最后,我运行apt-get install -f来替换我手动安装的.debs,并安装了正确的版本。
https://askubuntu.com/questions/578565
复制相似问题