Vulnerability Intelligence Report
CVE-2015-7547
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
No Active Exploit Signals
CVSS Base Score
8.1
HIGH
EPSS Probability:89.56%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 12.04, 14.04, 15.10 |
| hp | helion_openstack | 1.1.1, 2.0.0, 2.1.0 |
| hp | server_migration_pack | 7.5 |
| sophos | unified_threat_management_software | 9.319, 9.355 |
| suse | linux_enterprise_debuginfo | 11.0 |
| opensuse | opensuse | 13.2 |
| suse | linux_enterprise_desktop | 11.0, 12 |
| suse | linux_enterprise_server | 11.0, 12 |
| suse | linux_enterprise_software_development_kit | 11.0, 12 |
| suse | suse_linux_enterprise_server | 12 |
| oracle | exalogic_infrastructure | 1.0, 2.0 |
| f5 | big-ip_access_policy_manager | 12.0.0 |
| f5 | big-ip_advanced_firewall_manager | 12.0.0 |
| f5 | big-ip_analytics | 12.0.0 |
| f5 | big-ip_application_acceleration_manager | 12.0.0 |
| f5 | big-ip_application_security_manager | 12.0.0 |
| f5 | big-ip_domain_name_system | 12.0.0 |
| f5 | big-ip_link_controller | 12.0.0 |
| f5 | big-ip_local_traffic_manager | 12.0.0 |
| f5 | big-ip_policy_enforcement_manager | 12.0.0 |
| oracle | fujitsu_m10_firmware | all |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_hpc_node | 7.0 |
| redhat | enterprise_linux_hpc_node_eus | 7.2 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.2 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_workstation | 7.0 |
| gnu | glibc | 2.9, 2.10, 2.10.1, 2.11, 2.11.1, 2.11.2, 2.11.3, 2.12, 2.12.1, 2.12.2, 2.13, 2.14, 2.14.1, 2.15, 2.16, 2.17, 2.18, 2.19, 2.20, 2.21, 2.22 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
89.557%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2015-09-29T00:00:00 |
| Published | 2016-02-18T21:00:00 |
| Patch Date | 2015-07-13 |
| Last Updated | 2024-08-06T07:51:28 |
Community Chatter & Buzz