← All CVEs

CVE-2015-7547

high · 8.1

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

8.1
CVSS
91.0%
EPSS (exploit prob.)
100th
EPSS percentile
2016-02-18
Published

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
debiandebian_linux8.0
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.10
hphelion_openstack1.1.1
hphelion_openstack2.0.0
hphelion_openstack2.1.0
hpserver_migration_pack7.5
sophosunified_threat_management_software9.319
sophosunified_threat_management_software9.355
suselinux_enterprise_debuginfo11.0
suselinux_enterprise_debuginfo11.0
suselinux_enterprise_debuginfo11.0
opensuseopensuse13.2
suselinux_enterprise_desktop11.0
suselinux_enterprise_desktop11.0
suselinux_enterprise_desktop12
suselinux_enterprise_desktop12
suselinux_enterprise_server11.0
suselinux_enterprise_server11.0
suselinux_enterprise_server11.0
suselinux_enterprise_server11.0
suselinux_enterprise_server12
suselinux_enterprise_software_development_kit11.0
suselinux_enterprise_software_development_kit11.0
suselinux_enterprise_software_development_kit12
suselinux_enterprise_software_development_kit12
susesuse_linux_enterprise_server12
oracleexalogic_infrastructure1.0
oracleexalogic_infrastructure2.0
f5big-ip_access_policy_manager12.0.0
f5big-ip_advanced_firewall_manager12.0.0
f5big-ip_analytics12.0.0
f5big-ip_application_acceleration_manager12.0.0
f5big-ip_application_security_manager12.0.0
f5big-ip_domain_name_system12.0.0
f5big-ip_link_controller12.0.0
f5big-ip_local_traffic_manager12.0.0
f5big-ip_policy_enforcement_manager12.0.0
oraclefujitsu_m10_firmware<= 2290

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-7547