Interesting spot by Google, although the bug in glibc was reported in July 15. The bug has been out in the wild since 2008, which is interesting that it took so long to spot….. Or maybe not. May have been exploited for a while.

Anyway, if you have external facing services, using Linux, grab a patch, and fix the hole, because now everyone knows about it, and whilst in Googles view it is “hard” to exploit, there are a lot of smart hackers out there, so it is more of a “when” issue than a “how” issue.

BBC story on glibc bug

