CVE-2015-0235
published 2015-01-28CVE-2015-0235: Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to…
PriorityP275critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
94.86%
99.9th percentile
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.11.1 | 10.11.1 |
| apple | os_x_el_capitan_10.11.1_security_update_2015-004_yosemite_and_security_update_20 | — | — |
| apple | os_x_el_capitan_v10.11 | — | — |
| apple | os_x_yosemite_v10.10.4_and_security_update_2015-005 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | glibc | < glibc 2.18-1 (bookworm) | glibc 2.18-1 (bookworm) |
| gnu | glibc | >= 0 < 2.18-1 | 2.18-1 |
| gnu | glibc | >= 0 < 2.18-1 | 2.18-1 |
| gnu | glibc | >= 0 < 2.18-1 | 2.18-1 |
| gnu | glibc | >= 0 < 2.18-1 | 2.18-1 |
| gnu | glibc | >= 2.0 < 2.18 | 2.18 |
| ibm | pureapplication_system | — | — |
| ibm | pureapplication_system | — | — |
| ibm | pureapplication_system | — | — |
| ibm | security_access_manager_for_enterprise_single_sign-on | — | — |
| oracle | communications_application_session_controller | < 3.7.1 | 3.7.1 |
| oracle | communications_eagle_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_lsms | — | — |
| oracle | communications_policy_management | — | — |
| oracle | communications_policy_management | — | — |
| oracle | communications_policy_management | — | — |
| oracle | communications_policy_management | — | — |
| oracle | communications_policy_management | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets Exim SMTP servers; detect anomalous SMTP HELO/EHLO commands containing hostnames composed exclusively of digits and dots (e.g., matching ^[0-9.]+$) directed at port 25, which is the required malformed hostname format for triggering the overflow. ↗
- →Detection must be deployed on an application-by-application basis targeting programs that call gethostbyname() or gethostbyname2(); focus on Exim mail server, procmail, pppd as confirmed vulnerable applications. ↗
- →Snort signatures have been created to detect exploit attempts against the Exim mail server proof-of-concept; deploy IPS/NGFW rules for CVE-2015-0235 targeting SMTP traffic. ↗
- →The Metasploit module exploits Exim servers where helo_try_verify_hosts or helo_verify_hosts is enabled; monitor for SMTP sessions where the HELO hostname triggers a reverse DNS lookup against a digit-only hostname. ↗
- →Use Nessus plugin 22869 (Software Enumeration SSH) to identify hosts with vulnerable glibc versions installed as a detection/validation method. ↗
- →Qualys QID 123191 can be used to scan for and detect GHOST-vulnerable systems in enterprise environments. ↗
- ·The hostname used in exploitation must start with a digit, must not end with a dot, and must consist only of digits and dots — generic detection is not possible without application-specific context. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0HIGH
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC HMI Basic, SINUMERIK, and Ruggedcom APE GHOST Vulnerability
cisa_ics·2018-09-10·CVSS 10.0
[CRITICAL] Siemens SIMATIC HMI Basic, SINUMERIK, and Ruggedcom APE GHOST Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC HMI Basic, SINUMERIK, and Ruggedcom APE GHOST Vulnerability
Last RevisedSeptember 10, 2018
Alert CodeICSA-15-064-01
## OVERVIEW
The “GHOST"Further information about the GHOST vulnerability: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0235, web site last accessed March 05, 2015. vulnerability in the glibc library affects the Siemens SINUMERIK and SIMATIC HMI Basic applications. Siemens has produced an update for SINUMERIK that mitigates this vulnerability, and Siemens will be releasing an update for SIMATIC in the near future.
## AFFECTED PRODUCTS
T
CISA ICS
Siemens SIMATIC HMI Basic, SINUMERIK, and Ruggedcom APE GHOST Vulnerability (Update A)
cisa_ics·2015-03-05·CVSS 10.0
[CRITICAL] Siemens SIMATIC HMI Basic, SINUMERIK, and Ruggedcom APE GHOST Vulnerability (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC HMI Basic, SINUMERIK, and Ruggedcom APE GHOST Vulnerability (Update A)
Last RevisedAugust 27, 2018
Alert CodeICSA-15-064-01A
## OVERVIEW
This updated advisory is a follow-up to the original advisory titled ICSA-15-064-01 Siemens SIMATIC HMI Basic, SINUMERIK, and Ruggedcom APE GHOST Vulnerability that was published March 5, 2015, on the NCCIC/ICS-CERT web site.
The “GHOST”Further information about the GHOST vulnerability: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0235, web site last accessed March 05, 2015. vulnerability in the glibc library affect
Palo Alto
GHOST: glibc vulnerability
vendor_paloalto·2015-02-02·CVSS 10.0
CVE-2015-0235 [CRITICAL] CWE-119 GHOST: glibc vulnerability
GHOST: glibc vulnerability
The open source library “glibc” has been found to contain a recently discovered vulnerability (CVE-2015-0235, commonly referred to as “GHOST”) that has been demonstrated to enable remote code execution in some software. Palo Alto Networks software makes use of the vulnerable library, however there is no known exploitable condition in PAN-OS software enabled by this vulnerability at the time of this advisory. An update to PAN-OS will be made available that addresses CVE-2015-0235 in a regularly scheduled software maintenance update. (Ref # 74443)
The exploitability of CVE-2015-0235 on vulnerable systems is highly dependent on the architecture and design surrounding use of the vulnerable functions within the system, and exploitable conditions found across various
Cisco
GNU glibc gethostbyname Function Buffer Overflow Vulnerability
vendor_cisco·2015-01-29
CVE-2015-0235 [CRITICAL] CWE-119 GNU glibc gethostbyname Function Buffer Overflow Vulnerability
GNU glibc gethostbyname Function Buffer Overflow Vulnerability
On January 27, 2015, a buffer overflow vulnerability in the GNU C library (glibc) was publicly announced. This vulnerability is related to the various gethostbyname functions included in glibc and affects applications that call these functions. This vulnerability may allow an attacker to obtain sensitive information from an exploited system or, in some instances, perform remote code execution with the privileges of the application being exploited.
The glibc library is a commonly used third-party software component that is released by the GNU software project and a number of Cisco products are likely affected.
This advisory will be updated as additional information becomes available. Cisco will release free software updates t
Ubuntu
GNU C Library vulnerability
vendor_ubuntu·2015-01-27
CVE-2015-0235 GNU C Library vulnerability
Title: GNU C Library vulnerability
Summary: The GNU C Library could be made to crash or run programs.
It was discovered that a buffer overflow existed in the gethostbyname
and gethostbyname2 functions in the GNU C Library. An attacker could
use this issue to execute arbitrary code or cause an application crash,
resulting in a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
glibc: __nss_hostname_digits_dots() heap-based buffer overflow
vendor_redhat·2015-01-27·CVSS 10.0
CVE-2015-0235 [CRITICAL] CWE-131 glibc: __nss_hostname_digits_dots() heap-based buffer overflow
glibc: __nss_hostname_digits_dots() heap-based buffer overflow
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
A heap-based buffer overflow was found in glibc's __nss_hostname_digits_dots() function, which is used by the gethostbyname() and gethostbyname2() glibc function calls. A remote attacker able to make an application call either of these functions could use this flaw to execute arbitrary code with the permissions of the user running the application.
Debian
CVE-2015-0235: glibc - Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2...
vendor_debian·2015·CVSS 10.0
CVE-2015-0235 [CRITICAL] CVE-2015-0235: glibc - Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2...
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
Scope: local
bookworm: resolved (fixed in 2.18-1)
bullseye: resolved (fixed in 2.18-1)
forky: resolved (fixed in 2.18-1)
sid: resolved (fixed in 2.18-1)
trixie: resolved (fixed in 2.18-1)
Apple
CVE-2015-0235: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
vendor_apple·CVSS 10.0
CVE-2015-0235 [CRITICAL] CVE-2015-0235: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
Apple Security Update: About the security content of OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
Product: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
CVE: CVE-2015-0235
Component: CVE-2015-0235
Apple
CVE-2015-0235: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 10.0
CVE-2015-0235 [CRITICAL] CVE-2015-0235: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-0235
Component: CVE-2015-0235
Apple
CVE-2015-0235: OS X El Capitan v10.11
vendor_apple·CVSS 10.0
CVE-2015-0235 [CRITICAL] CVE-2015-0235: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2015-0235
Component: CVE-2015-0235
Cisco
GNU glibc gethostbyname Function Buffer Overflow Vulnerability
vendor_cisco
CVE-2015-0235 GNU glibc gethostbyname Function Buffer Overflow Vulnerability
CVE-2015-0235: GNU glibc gethostbyname Function Buffer Overflow Vulnerability
On January 27, 2015, a buffer overflow vulnerability in the GNU C library (glibc) was publicly announced. This vulnerability is related to the various gethostbyname functions included in glibc and affects applications that call these functions. This vulnerability may allow an attacker to obtain sensitive information from an exploited system or, in some instances, perform remote code execution with the privileges of the application being exploited. The glibc library is a commonly used third-party software component that is released by the GNU software project and a number of Cisco products are likely affected. This advisory will be updated as additional information becomes available. Cisco will release free softwa
GHSA
GHSA-jwcp-p679-fcr4: Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2
ghsa_unreviewed·2022-05-13
CVE-2015-0235 [HIGH] CWE-787 GHSA-jwcp-p679-fcr4: Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
OSV
CVE-2015-0235: Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2
osv·2015-01-28·CVSS 10.0
CVE-2015-0235 [CRITICAL] CVE-2015-0235: Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
No detection rules found.
Exploit-DB
Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)
exploitdb·2015-03-18·CVSS 10.0
CVE-2015-0235 [CRITICAL] Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)
Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit4 'Exim GHOST (glibc gethostbyname) Buffer Overflow',
'Description' => %q(
This module remotely exploits CVE-2015-0235 (a.k.a. GHOST, a heap-based
buffer overflow in the GNU C Library's gethostbyname functions) on x86
and x86_64 GNU/Linux systems that run the Exim mail server. Technical
information about the exploitation can be found in the original GHOST
advisory, and in the source code of this module.
SERVER-SIDE REQUIREMENTS (Exim)
The remote system must use a vulnerable version of the GNU C Library:
the first exploitable version is glibc-2.6, the
Exploit-DB
Exim ESMTP 4.80 - glibc gethostbyname Denial of Service
exploitdb·2015-01-29·CVSS 10.0
CVE-2015-0235 [CRITICAL] Exim ESMTP 4.80 - glibc gethostbyname Denial of Service
Exim ESMTP 4.80 - glibc gethostbyname Denial of Service
---
# Exploit Title: [Exim ESMTP GHOST DoS PoC Exploit]
# Date: [1/29/2015]
# Exploit Author: [1N3]
# Vendor Homepage: [www.exim.org]
# Version: [4.80 or less]
# Tested on: [debian-7-7-64b]
# CVE : [2015-0235]
#!/usr/bin/python
# Exim ESMTP DoS Exploit by 1N3 v20150128
# CVE-2015-0235 GHOST glibc gethostbyname buffer overflow
# http://crowdshield.com
#
# USAGE: python ghost-smtp-dos.py
#
# Escape character is '^]'.
# 220 debian-7-7-64b ESMTP Exim 4.80 ...
# HELO
# 00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Metasploit
Exim GHOST (glibc gethostbyname) Buffer Overflow
metasploit·CVSS 10.0
CVE-2015-0235 [CRITICAL] Exim GHOST (glibc gethostbyname) Buffer Overflow
Exim GHOST (glibc gethostbyname) Buffer Overflow
This module remotely exploits CVE-2015-0235, aka GHOST, a heap-based buffer overflow in the GNU C Library's gethostbyname functions on x86 and x86_64 GNU/Linux systems that run the Exim mail server.
Metasploit
WordPress XMLRPC GHOST Vulnerability Scanner
metasploit
WordPress XMLRPC GHOST Vulnerability Scanner
WordPress XMLRPC GHOST Vulnerability Scanner
This module can be used to determine hosts vulnerable to the GHOST vulnerability via a call to the WordPress XMLRPC interface. If the target is vulnerable, the system will segfault and return a server error. On patched systems, a normal XMLRPC error is returned.
Qualys
Ghost Vulnerability: Remote Code Execution Exploit | Qualys
blogs_qualys·2015-03-17·CVSS 10.0
CVE-2015-0235 [CRITICAL] Ghost Vulnerability: Remote Code Execution Exploit | Qualys
## Table of Contents
About the GHOST Vulnerability
How Metasploit Exploits Exim Vulnerability for Remote Shell Access
Metasploit Module for Exploiting the Exim GHOST Vulnerability
A demonstration of remote code execution of the GHOST vulnerability, delivered as a standalone Metasploit module, is now available. The module remotely exploits CVE-2015-0235 (a.k.a. GHOST, a heap-based buffer overflow in the GNU C Library’s gethostbyname functions) on x86 and x86_64 GNU/Linux systems that run the Exim mail server.
## About the GHOST Vulnerability
The GHOST vulnerability can be triggered both locally and remotely via all the gethostbyname*() functions in the glibc library that is a core part of the Linux operating system.
The first vulnerable version of the GNU C Library affected by this i
Qualys
Ghost Vulnerability: Remote Code Execution Exploit | Qualys
blogs_qualys·2015-03-17·CVSS 10.0
CVE-2015-0235 [CRITICAL] Ghost Vulnerability: Remote Code Execution Exploit | Qualys
#### Table of Contents
- About the GHOST Vulnerability
- How Metasploit Exploits Exim Vulnerability for Remote Shell Access
- Metasploit Module for Exploiting the Exim GHOST Vulnerability
A demonstration of remote code execution of the GHOST vulnerability, delivered as a standalone Metasploit module, is now available. The module remotely exploits CVE-2015-0235 (a.k.a. GHOST, a heap-based buffer overflow in the GNU C Library’s gethostbyname functions) on x86 and x86_64 GNU/Linux systems that run the Exim mail server.
## About the GHOST Vulnerability
The GHOST vulnerability can be triggered both locally and remotely via all the gethostbyname*() functions in the glibc library that is a core part of the Linux operating system.
The first vulnerable version of the GNU C Library affected by
Tenable
GHOST in Linux
blogs_tenable·2015-01-29·CVSS 10.0
[CRITICAL] GHOST in Linux
by Cody Dumont January 29, 2015
The newest high profile vulnerability is the GNU C Library (“glibc”) vulnerability, dubbed “GHOST” by the media. Organizations should take a proactive approach to patching these high profile vulnerabilities. This dashboard helps identify vulnerable systems using several methods of identification.
The dashboard and its components are available in the SecurityCenter Feed, a comprehensive collection of dashboards, reports, assurance report cards and assets. The dashboard can be easily located in the SecurityCenter Feed under the category Security Industry Trends .
The dashboard requirements are:
SecurityCenter 4.8.2
Nessus 6.1.1
The dashboard uses three methods of identifying vulnerable systems. The first, and most accurate, method uses the CVE-2015-0235
Tenable
GHOST in Linux
blogs_tenable·2015-01-29·CVSS 10.0
[CRITICAL] GHOST in Linux
by Cody Dumont January 29, 2015
The newest high profile vulnerability is the GNU C Library (“glibc”) vulnerability, dubbed “GHOST” by the media. Organizations should take a proactive approach to patching these high profile vulnerabilities. This report helps identify vulnerable systems using several methods of identification.
The report is available in the SecurityCenter Feed, a comprehensive collection of dashboards, reports, assurance report cards and assets. The report can be easily located in the SecurityCenter Feed under the category Security Industry Trends . The report requirements are:
SecurityCenter 4.8.2
Nessus 6.1.1
The report uses three methods of identifying vulnerable systems. The first, and most accurate, method uses the CVE-2015-0235 filter to identify the systems scann
Talos
CVE-2015-0235: A GHOST in the Machine
blogs_talos·2015-01-28·CVSS 10.0
CVE-2015-0235 [CRITICAL] CVE-2015-0235: A GHOST in the Machine
This post was authored by Nick Biasini, Earl Carter, Alex Chiu and Jaeson Schultz
On Tuesday January 27, 2015, security researchers from Qualys published information concerning a 0-day vulnerability in the GNU C library. The vulnerability, known as “GHOST” (a.k.a. CVE-2015-0235), is a buffer overflow in the __nss_hostname_digits_dots() function. As a proof-of-concept, Qualys has detailed a remote exploit for the Exim mail server that bypasses all existing protections, and results in arbitrary command execution. Qualys intends to release the exploit as a Metasploit module.
CVE-2015-0235 affects the functions gethostbyname() and gethostbyname2() --functions originally used to resolve a hostname to an IP address. However, these functions have been deprecated for approximately fifteen years,
Talos
CVE-2015-0235: A GHOST in the Machine
blogs_talos·2015-01-28·CVSS 10.0
CVE-2015-0235 [CRITICAL] CVE-2015-0235: A GHOST in the Machine
## CVE-2015-0235: A GHOST in the Machine
This post was authored by Nick Biasini , Earl Carter , Alex Chiu and Jaeson Schultz
On Tuesday January 27, 2015, security researchers from Qualys published information concerning a 0-day vulnerability in the GNU C library. The vulnerability, known as “GHOST” (a.k.a. CVE-2015-0235), is a buffer overflow in the __nss_hostname_digits_dots() function. As a proof-of-concept, Qualys has detailed a remote exploit for the Exim mail server that bypasses all existing protections, and results in arbitrary command execution. Qualys intends to release the exploit as a Metasploit module.
CVE-2015-0235 affects the functions gethostbyname() and gethostbyname2() --functions originally used to resolve a hostname to an IP address. However, these functions have been
Qualys
GHOST Vulnerability CVE-2015-0235 | Linux glibc RCE Bug | Qualys
blogs_qualys·2015-01-27·CVSS 10.0
CVE-2015-0235 [CRITICAL] GHOST Vulnerability CVE-2015-0235 | Linux glibc RCE Bug | Qualys
The GHOST vulnerability is a serious weakness in the Linux glibc library. It allows attackers to remotely take complete control of the victim system without having any prior knowledge of system credentials. CVE-2015-0235 has been assigned to this issue.
Qualys security researchers discovered this bug and worked closely with Linux distribution vendors. And as a result of that we are releasing this advisory today as a co-ordinated effort, and patches for all distribution are available January 27, 2015.
## What is glibc?
The GNU C Library or glibc is an implementation of the standard C library and a core part of the Linux operating system. Without this library a Linux system will not function.
## What is the vulnerability?
During a code audit Qualys researchers discovered a buffer overfl
Qualys
GHOST Vulnerability CVE-2015-0235 | Linux glibc RCE Bug | Qualys
blogs_qualys·2015-01-27·CVSS 10.0
CVE-2015-0235 [CRITICAL] GHOST Vulnerability CVE-2015-0235 | Linux glibc RCE Bug | Qualys
```
The GHOST vulnerability is a serious weakness in the Linux glibc library. It allows attackers to remotely take complete control of the victim system without having any prior knowledge of system credentials. CVE-2015-0235 has been assigned to this issue.
```
Qualys security researchers discovered this bug and worked closely with Linux distribution vendors. And as a result of that we are releasing this advisory today as a co-ordinated effort, and patches for all distribution are available January 27, 2015.
### What is glibc?
The GNU C Library or glibc is an implementation of the standard C library and a core part of the Linux operating system. Without this library a Linux system will not function.
### What is the vulnerability?
During a code audit Qualys researchers discovered a buf
Tenable
Tenable Responds to CVE-2015-0235: GHOST (Updated)
blogs_tenable·2015-01-27·CVSS 10.0
[CRITICAL] Tenable Responds to CVE-2015-0235: GHOST (Updated)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2015-7547 glibc: getaddrinfo stack-based buffer overflow
bugzilla·2015-12-22·CVSS 8.1
CVE-2015-7547 [HIGH] CVE-2015-7547 glibc: getaddrinfo stack-based buffer overflow
CVE-2015-7547 glibc: getaddrinfo stack-based buffer overflow
A stack-based buffer overflow was found in libresolv when invoked from nss_dns, allowing specially crafted DNS responses to seize control of EIP in the DNS client.
The buffer overflow occurs in the functions send_dg (send datagram) and send_vc (send TCP) for the NSS module libnss_dns.so.2 when calling getaddrinfo with AF_UNSPEC family, or in some cases AF_INET6 family. The use of AF_UNSPEC (or AF_INET6 in some cases) triggers the low-level resolver code to send out two parallel queries for A and AAAA. A mismanagement of the buffers used for those queries could result in the response of a query writing beyond the alloca allocated buffer created by __res_nquery.
Discussion:
Acknowledgements:
This issue was discovered by the Go
Bugzilla
update for CVE-2015-0235 missed by yum --security
bugzilla·2015-01-28·CVSS 10.0
CVE-2015-0235 [CRITICAL] update for CVE-2015-0235 missed by yum --security
update for CVE-2015-0235 missed by yum --security
Description of problem:
Security updates relying on yum --security (e.g. via yum-cron) don't pick up the GHOST fix.
I don't know how yum-security works, so I don't know whether the bug is actually in the repo, glibc package, or elsewhere.
Version-Release number of selected component (if applicable):
2.12-1.149.el6_6.5
How reproducible:
Steps to Reproduce:
# yum --security check-update glibc\*
Actual results:
# yum --security check-update glibc\*
Loaded plugins: auto-update-debuginfo, changelog, downloadonly, etckeeper,
: fastestmirror, filter-data, merge-conf, post-transaction-
: actions, priorities, product-id, protectbase, refresh-
: packagekit, security, subscription-manager, verify, versionlock
Loading mirror speeds from cach
Bugzilla
CVE-2015-0235 glibc: __nss_hostname_digits_dots() heap-based buffer overflow
bugzilla·2015-01-19·CVSS 10.0
CVE-2015-0235 [CRITICAL] CVE-2015-0235 glibc: __nss_hostname_digits_dots() heap-based buffer overflow
CVE-2015-0235 glibc: __nss_hostname_digits_dots() heap-based buffer overflow
A heap-based buffer overflow was found in __nss_hostname_digits_dots(), which is used by the gethostbyname() and gethostbyname2() glibc function call. A remote attacker could use this flaw to execute arbitary code with the permissions of the user running the application.
Discussion:
Upstream patch:
https://sourceware.org/git/?p=glibc.git;a=commit;h=d5dd6189d506068ed11c8bfa1e1e9bffde04decd
---
Public via:
http://www.frsag.org/pipermail/frsag/2015-January/005722.html
---
Acknowledgements:
Red Hat would like to thank Qualys for reporting this issue.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Via RHSA-2015:0090 https://rhn.redhat.com/errata/RHSA-2015-0090.html
arXiv
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
arxiv_fulltext·2025-02-12
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
frontmatter
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
[1,2]0000-0002-2288-9010 Stefan Tatschnercor1
[1,3,4]0000-0002-1094-4828 Michael P. Heinl
[2]0009-0008-0767-8208 Nicole Pappler
[1]0009-0001-7615-7579 Tobias Specht
[5]0000-0002-1658-1140 Sven Plaga
[2]0000-0002-3375-8200 Thomas Newe
[cor1]Corresponding author
[1]organization=Fraunhofer AISEC,
city=Garching bei München,
state=Bavaria,
country=Germany
[2]organization=University of Limerick,
city=Limerick,
addressline=V94 T9PX,
country=Ireland
[3]organization=Technical University of Munich,
city=Garching bei München,
state=Bavaria,
country=Germany
[4]organization=Munich University of Applied Sciences HM,
city=Munich,
state=Bavaria,
country=Germany
[5]org
arXiv
Automating the Generation of Cyber Range Virtual Scenarios with VSDL
arxiv_fulltext·2023-01-30
Automating the Generation of Cyber Range Virtual Scenarios with VSDL
Automating the Generation of Cyber Range Virtual Scenarios with VSDL
Automating the Generation of CR Virtual Scenarios with VSDL
Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications (JoWUA)
13
1
33
Mar. 2022
10.22667/JOWUA.2022.03.31.0033
Gabriele Costa^1, Enrico Russo^2Corresponding author: Department of Informatics, Bioengineering, Robotics, and Systems Engineering (DIBRIS), Viale Causa, 13, 16145 Genoa, Italy, and Alessandro Armando^2\ 1em]
^1IMT School for Advanced Studies, Lucca 55100 Italy
[email protected]\ 1em]
^2University of Genoa, DIBRIS, Genoa 16145 Italy
[email protected], [email protected]
Received: October 17, 2022; Accepted: December 4, 2022; Published: December 31, 2022
Costa, Russo and Armando
## Abstract
A
http://blogs.sophos.com/2015/01/29/sophos-products-and-the-ghost-vulnerability-affecting-linux/http://linux.oracle.com/errata/ELSA-2015-0090.htmlhttp://linux.oracle.com/errata/ELSA-2015-0092.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Oct/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://marc.info/?l=bugtraq&m=142296726407499&w=2http://marc.info/?l=bugtraq&m=142721102728110&w=2http://marc.info/?l=bugtraq&m=142722450701342&w=2http://marc.info/?l=bugtraq&m=142781412222323&w=2http://marc.info/?l=bugtraq&m=143145428124857&w=2http://packetstormsecurity.com/files/130171/Exim-ESMTP-GHOST-Denial-Of-Service.htmlhttp://packetstormsecurity.com/files/130768/EMC-Secure-Remote-Services-GHOST-SQL-Injection-Command-Injection.htmlhttp://packetstormsecurity.com/files/130974/Exim-GHOST-glibc-gethostbyname-Buffer-Overflow.htmlhttp://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.htmlhttp://packetstormsecurity.com/files/167552/Nexans-FTTO-GigaSwitch-Outdated-Components-Hardcoded-Backdoor.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0126.htmlhttp://seclists.org/fulldisclosure/2015/Jan/111http://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2021/Sep/0http://seclists.org/fulldisclosure/2022/Jun/36http://seclists.org/oss-sec/2015/q1/269http://seclists.org/oss-sec/2015/q1/274http://secunia.com/advisories/62517http://secunia.com/advisories/62640http://secunia.com/advisories/62667http://secunia.com/advisories/62680http://secunia.com/advisories/62681http://secunia.com/advisories/62688http://secunia.com/advisories/62690http://secunia.com/advisories/62691http://secunia.com/advisories/62692http://secunia.com/advisories/62698http://secunia.com/advisories/62715http://secunia.com/advisories/62758http://secunia.com/advisories/62812http://secunia.com/advisories/62813http://secunia.com/advisories/62816http://secunia.com/advisories/62865http://secunia.com/advisories/62870http://secunia.com/advisories/62871http://secunia.com/advisories/62879http://secunia.com/advisories/62883http://support.apple.com/kb/HT204942http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150128-ghosthttp://www-01.ibm.com/support/docview.wss?uid=swg21695695http://www-01.ibm.com/support/docview.wss?uid=swg21695774http://www-01.ibm.com/support/docview.wss?uid=swg21695835http://www-01.ibm.com/support/docview.wss?uid=swg21695860http://www-01.ibm.com/support/docview.wss?uid=swg21696131http://www-01.ibm.com/support/docview.wss?uid=swg21696243http://www-01.ibm.com/support/docview.wss?uid=swg21696526http://www-01.ibm.com/support/docview.wss?uid=swg21696600http://www-01.ibm.com/support/docview.wss?uid=swg21696602http://www-01.ibm.com/support/docview.wss?uid=swg21696618http://www.debian.org/security/2015/dsa-3142http://www.idirect.net/Partners/~/media/Files/CVE/iDirect-Posted-Common-Vulnerabilities-and-Exposures.pdfhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:039http://www.openwall.com/lists/oss-security/2021/05/04/7http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/archive/1/534845/100/0/threadedhttp://www.securityfocus.com/bid/72325http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1032909http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0https://bto.bluecoat.com/security-advisory/sa90https://cert-portal.siemens.com/productcert/pdf/ssa-994726.pdfhttps://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerabilityhttps://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04874668https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixeshttps://kb.juniper.net/InfoCenter/index?page=content&id=JSA10671https://kc.mcafee.com/corporate/index?page=content&id=SB10100https://seclists.org/bugtraq/2019/Jun/14https://security.gentoo.org/glsa/201503-04https://security.netapp.com/advisory/ntap-20150127-0001/https://support.apple.com/HT205267https://support.apple.com/HT205375https://www.arista.com/en/support/advisories-notices/security-advisories/1053-security-advisory-9https://www.f-secure.com/en/web/labs_global/fsc-2015-1https://www.qualys.com/research/security-advisories/GHOST-CVE-2015-0235.txthttps://www.sophos.com/en-us/support/knowledgebase/121879.aspxhttp://blogs.sophos.com/2015/01/29/sophos-products-and-the-ghost-vulnerability-affecting-linux/http://linux.oracle.com/errata/ELSA-2015-0090.htmlhttp://linux.oracle.com/errata/ELSA-2015-0092.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Oct/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://marc.info/?l=bugtraq&m=142296726407499&w=2http://marc.info/?l=bugtraq&m=142721102728110&w=2http://marc.info/?l=bugtraq&m=142722450701342&w=2http://marc.info/?l=bugtraq&m=142781412222323&w=2
+ 80 more references
2015-01-28
Published