← Back to CVE List
Vulnerability Intelligence Report

CVE-2015-7547

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

No Active Exploit Signals
CVSS Base Score
8.1
HIGH
EPSS Probability:89.56%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
debian debian_linux 8.0
canonical ubuntu_linux 12.04, 14.04, 15.10
hp helion_openstack 1.1.1, 2.0.0, 2.1.0
hp server_migration_pack 7.5
sophos unified_threat_management_software 9.319, 9.355
suse linux_enterprise_debuginfo 11.0
opensuse opensuse 13.2
suse linux_enterprise_desktop 11.0, 12
suse linux_enterprise_server 11.0, 12
suse linux_enterprise_software_development_kit 11.0, 12
suse suse_linux_enterprise_server 12
oracle exalogic_infrastructure 1.0, 2.0
f5 big-ip_access_policy_manager 12.0.0
f5 big-ip_advanced_firewall_manager 12.0.0
f5 big-ip_analytics 12.0.0
f5 big-ip_application_acceleration_manager 12.0.0
f5 big-ip_application_security_manager 12.0.0
f5 big-ip_domain_name_system 12.0.0
f5 big-ip_link_controller 12.0.0
f5 big-ip_local_traffic_manager 12.0.0
f5 big-ip_policy_enforcement_manager 12.0.0
oracle fujitsu_m10_firmware all
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_hpc_node 7.0
redhat enterprise_linux_hpc_node_eus 7.2
redhat enterprise_linux_server 7.0
redhat enterprise_linux_server_aus 7.2
redhat enterprise_linux_server_eus 7.2
redhat enterprise_linux_workstation 7.0
gnu glibc 2.9, 2.10, 2.10.1, 2.11, 2.11.1, 2.11.2, 2.11.3, 2.12, 2.12.1, 2.12.2, 2.13, 2.14, 2.14.1, 2.15, 2.16, 2.17, 2.18, 2.19, 2.20, 2.21, 2.22

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
89.557%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2015-09-29T00:00:00
Published2016-02-18T21:00:00
Patch Date2015-07-13
Last Updated2024-08-06T07:51:28

LINK COPIED TO CLIPBOARD