cbcvebase.
CVE-2015-0235
published 2015-01-28

CVE-2015-0235: Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to…

PriorityP275critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
94.86%
99.9th percentile
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x< 10.11.110.11.1
appleos_x_el_capitan_10.11.1_security_update_2015-004_yosemite_and_security_update_20
appleos_x_el_capitan_v10.11
appleos_x_yosemite_v10.10.4_and_security_update_2015-005
debiandebian_linux
debiandebian_linux
debianglibc< glibc 2.18-1 (bookworm)glibc 2.18-1 (bookworm)
gnuglibc>= 0 < 2.18-12.18-1
gnuglibc>= 0 < 2.18-12.18-1
gnuglibc>= 0 < 2.18-12.18-1
gnuglibc>= 0 < 2.18-12.18-1
gnuglibc>= 2.0 < 2.182.18
ibmpureapplication_system
ibmpureapplication_system
ibmpureapplication_system
ibmsecurity_access_manager_for_enterprise_single_sign-on
oraclecommunications_application_session_controller< 3.7.13.7.1
oraclecommunications_eagle_application_processor
oraclecommunications_eagle_lnp_application_processor
oraclecommunications_lsms
oraclecommunications_policy_management
oraclecommunications_policy_management
oraclecommunications_policy_management
oraclecommunications_policy_management
oraclecommunications_policy_management

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://www.qualys.com/research/security-advisories/exim_ghost_bof.rb
urlhttps://www.qualys.com/research/security-advisories/GHOST-CVE-2015-0235.txt
  • Exploit targets Exim SMTP servers; detect anomalous SMTP HELO/EHLO commands containing hostnames composed exclusively of digits and dots (e.g., matching ^[0-9.]+$) directed at port 25, which is the required malformed hostname format for triggering the overflow.
  • Detection must be deployed on an application-by-application basis targeting programs that call gethostbyname() or gethostbyname2(); focus on Exim mail server, procmail, pppd as confirmed vulnerable applications.
  • Snort signatures have been created to detect exploit attempts against the Exim mail server proof-of-concept; deploy IPS/NGFW rules for CVE-2015-0235 targeting SMTP traffic.
  • The Metasploit module exploits Exim servers where helo_try_verify_hosts or helo_verify_hosts is enabled; monitor for SMTP sessions where the HELO hostname triggers a reverse DNS lookup against a digit-only hostname.
  • Use Nessus plugin 22869 (Software Enumeration SSH) to identify hosts with vulnerable glibc versions installed as a detection/validation method.
  • Qualys QID 123191 can be used to scan for and detect GHOST-vulnerable systems in enterprise environments.
  • ·The hostname used in exploitation must start with a digit, must not end with a dot, and must consist only of digits and dots — generic detection is not possible without application-specific context.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0HIGH
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.