PT-2015-6828 · Gnu+4 · Glibc+4

Andreas Schwab

+1

·

Publicado

2015-11-19

·

Atualizado

2023-02-12

·

CVE-2015-5277

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.20
Description The issue is related to the get contents function in the Name Service Switch (NSS) in GNU C Library, which might allow local users to cause a denial of service or gain privileges via a long line in the NSS files database.
Recommendations For versions prior to 2.20, update to version 2.20 or later to resolve the issue. As a temporary workaround, consider restricting access to the NSS files database to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2084
CESA-2015_2172
CVE-2015-5277
RHSA-2015:2172
RHSA-2015:2589
RHSA-2015_2172
USN-2985-1
USN-2985-2

Produtos afetados

Alt Linux
Centos
Red Hat
Ubuntu
Glibc