CVE-2015-0235

Modified
Published: 28 Jan 2015, 19:00
Last modified:06 Aug 2024, 04:03

Vulnerability Summary

Overall Risk (default)
critical
90/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
84.87% CRITICAL
85% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
16 found
Dark Web
Not detected

Timeline

28 Jan 2015, 19:00
Published
Vulnerability first disclosed
06 Aug 2024, 04:03
Last Modified
Vulnerability information updated

Description

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

CVSS Metrics

  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 84.87% Percentile: 99%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • applemac_os_x

    < 10.11.1

  • debiandebian_linux

    7.0 | 8.0

  • gnuglibc

    ≥ 2.0, < 2.18

  • ibmpureapplication_system

    1.0.0.0 | 1.1.0.0 | 2.0.0.0

  • ibmsecurity_access_manager_for_enterprise_single_sign-on

    8.2

  • oraclecommunications_application_session_controller

    < 3.7.1

  • oraclecommunications_eagle_application_processor

    16.0

  • oraclecommunications_eagle_lnp_application_processor

    10.0

  • oraclecommunications_lsms

    13.1

  • oraclecommunications_policy_management

    9.7.3 | 9.9.1 | 10.4.1 | 11.5 | 12.1.1

  • oraclecommunications_session_border_controller

    < 7.2.0 | 7.2.0 | 8.0.0

  • oraclecommunications_user_data_repository

    ≥ 10.0.0, ≤ 10.0.1

  • oraclecommunications_webrtc_session_controller

    7.0 | 7.1 | 7.2

  • oracleexalogic_infrastructure

    1.0 | 2.0

  • oraclelinux

    5 | 7:0

  • oraclevm_virtualbox

    < 5.1.24

  • UnknownPHP

    ≥ 5.4.0, < 5.4.38 | ≥ 5.5.0, < 5.5.22 | ≥ 5.6.0, < 5.6.6

  • redhatvirtualization

    6.0

References (90)