Info: http://ma.ttias.be/critical-glibc-update-cve-2015-0235-gethostbyname-calls/
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-0235
This issue affects anyone doing DNS lookups, including reverse DNS lookups.
XenForo explicitly does DNS lookups of IPs at registration time, and as such is a vector for this being exploited.
But you really want to patch this ASAP, as the number of things which do reverse DNS lookup on a Linux is crazy long.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-0235
This issue affects anyone doing DNS lookups, including reverse DNS lookups.
XenForo explicitly does DNS lookups of IPs at registration time, and as such is a vector for this being exploited.
But you really want to patch this ASAP, as the number of things which do reverse DNS lookup on a Linux is crazy long.