CVE-2015-7547

Advisory lineage Upstream: 0 Downstream: 17
Modified
Published: 18 Feb 2016, 21:00
Last modified:06 Aug 2024, 07:51

Vulnerability Summary

Overall Risk (default)
high
61/100
CVSS Score
8.1 HIGH
v3.0 (nvd)
EPSS Score
93.91% CRITICAL
94% probability +0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

18 Feb 2016, 21:00
Published
Vulnerability first disclosed
06 Aug 2024, 07:51
Last Modified
Vulnerability information updated

Description

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

CVSS Metrics

  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 93.91% Percentile: 100%

Techniques & Countermeasures

  • CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer

    The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.10

  • debiandebian_linux

    8.0

  • f5big-ip_access_policy_manager

    12.0.0

  • f5big-ip_advanced_firewall_manager

    12.0.0

  • f5big-ip_analytics

    12.0.0

  • f5big-ip_application_acceleration_manager

    12.0.0

  • f5big-ip_application_security_manager

    12.0.0

  • f5big-ip_domain_name_system

    12.0.0

  • f5big-ip_link_controller

    12.0.0

  • f5big-ip_local_traffic_manager

    12.0.0

  • f5big-ip_policy_enforcement_manager

    12.0.0

  • gnuglibc

    2.9 | 2.10 | 2.10.1 | 2.11 | 2.11.1 | 2.11.2 | 2.11.3 | 2.12 | 2.12.1 | 2.12.2 | 2.13 | 2.14 | 2.14.1 | 2.15 | 2.16 | 2.17 | 2.18 | 2.19 | 2.20 | 2.21 | 2.22

  • hphelion_openstack

    1.1.1 | 2.0.0 | 2.1.0

  • hpserver_migration_pack

    7.5

  • opensuseopensuse

    13.2

  • oracleexalogic_infrastructure

    1.0 | 2.0

  • oraclefujitsu_m10_firmware

    ≤ 2290

  • redhatenterprise_linux_desktop

    7.0

  • redhatenterprise_linux_hpc_node

    7.0

  • redhatenterprise_linux_hpc_node_eus

    7.2

  • redhatenterprise_linux_server

    7.0

  • redhatenterprise_linux_server_aus

    7.2

  • redhatenterprise_linux_server_eus

    7.2

  • redhatenterprise_linux_workstation

    7.0

  • sophosunified_threat_management_software

    9.319 | 9.355

  • suselinux_enterprise_debuginfo

    11.0:sp2 | 11.0:sp3 | 11.0:sp4

  • suselinux_enterprise_desktop

    11.0:sp3 | 11.0:sp4 | 12 | 12:sp1

  • suselinux_enterprise_server

    11.0:sp2 | 11.0:sp3 | 11.0:sp4 | 12:sp1

  • suselinux_enterprise_software_development_kit

    11.0:sp3 | 11.0:sp4 | 12 | 12:sp1

  • susesuse_linux_enterprise_server

    12

References (75)