PT-2015-1000 · Gnu+8 · Glibc+11
Hanno Böck
·
Published
2012-02-17
·
Updated
2025-12-10
·
CVE-2015-0235
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
glibc versions 2.2 through 2.17
Description
The issue is related to a heap-based buffer overflow in the
nss hostname digits dots function in glibc, which can be exploited via the gethostbyname or gethostbyname2 functions. This vulnerability may allow an attacker to execute arbitrary code or obtain sensitive information from an exploited system. The glibc library is a commonly used third-party software component, and a number of products are likely affected. Exploitation can be done remotely.Recommendations
For glibc versions 2.2 through 2.17, update to version 2.18 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
gethostbyname and gethostbyname2 functions until a patch is available.
Avoid using the nss hostname digits dots function in affected API endpoints until the issue is resolved.
At the moment, there is no information about other newer versions that contain a fix for this vulnerability.Exploit
Fix
RCE
DoS
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Check Point Gaia
Cisco Ios Xe
Cisco Ios Xr
Cisco Nexus
Cisco Wls
Huawei Vrp
Red Hat
Suse
Virtualbox
Glibc