PT-2015-6828 · Gnu+4 · Glibc+4

Andreas Schwab

+1

·

Published

2015-11-19

·

Updated

2023-02-12

·

CVE-2015-5277

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.20
Description The issue is related to the get contents function in the Name Service Switch (NSS) in GNU C Library, which might allow local users to cause a denial of service or gain privileges via a long line in the NSS files database.
Recommendations For versions prior to 2.20, update to version 2.20 or later to resolve the issue. As a temporary workaround, consider restricting access to the NSS files database to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2084
CESA-2015_2172
CVE-2015-5277
RHSA-2015:2172
RHSA-2015:2589
RHSA-2015_2172
USN-2985-1
USN-2985-2

Affected Products

Alt Linux
Centos
Red Hat
Ubuntu
Glibc