cbcvebase.
CVE-2015-0235
published 2015-01-28

CVE-2015-0235: Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to…

critical10CVSS 3.1
AVNACLAuNCCICAC
EXPLOIT
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x< 10.11.110.11.1
appleos_x_el_capitan_10.11.1_security_update_2015-004_yosemite_and_security_update_20
appleos_x_el_capitan_v10.11
appleos_x_yosemite_v10.10.4_and_security_update_2015-005
debiandebian_linux
debiandebian_linux
debianglibc< glibc 2.18-1 (bookworm)glibc 2.18-1 (bookworm)
gnuglibc>= 0 < 2.18-12.18-1
gnuglibc>= 0 < 2.18-12.18-1
gnuglibc>= 0 < 2.18-12.18-1
gnuglibc>= 0 < 2.18-12.18-1
gnuglibc>= 2.0 < 2.182.18
ibmpureapplication_system
ibmpureapplication_system
ibmpureapplication_system
ibmsecurity_access_manager_for_enterprise_single_sign-on
oraclecommunications_application_session_controller< 3.7.13.7.1
oraclecommunications_eagle_application_processor
oraclecommunications_eagle_lnp_application_processor
oraclecommunications_lsms
oraclecommunications_policy_management
oraclecommunications_policy_management
oraclecommunications_policy_management
oraclecommunications_policy_management
oraclecommunications_policy_management

CVSS provenance

nvd10.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL