PT-2015-1000 · Gnu+8 · Glibc+11
Hanno Böck
·
Publicado
2012-02-17
·
Atualizado
2025-12-10
·
CVE-2015-0235
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
glibc versions 2.2 through 2.17
Description
The issue is related to a heap-based buffer overflow in the
nss hostname digits dots function in glibc, which can be exploited via the gethostbyname or gethostbyname2 functions. This vulnerability may allow an attacker to execute arbitrary code or obtain sensitive information from an exploited system. The glibc library is a commonly used third-party software component, and a number of products are likely affected. Exploitation can be done remotely.Recommendations
For glibc versions 2.2 through 2.17, update to version 2.18 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
gethostbyname and gethostbyname2 functions until a patch is available.
Avoid using the nss hostname digits dots function in affected API endpoints until the issue is resolved.
At the moment, there is no information about other newer versions that contain a fix for this vulnerability.Exploit
Correção
RCE
DoS
Memory Corruption
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Check Point Gaia
Cisco Ios Xe
Cisco Ios Xr
Cisco Nexus
Cisco Wls
Huawei Vrp
Red Hat
Suse
Virtualbox
Glibc