cbcvebase.
CVE-2015-7547
published 2016-02-18

CVE-2015-7547: Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before…

high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EXPLOIT
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

Affected

65 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianglibc< glibc 2.21-8 (bookworm)glibc 2.21-8 (bookworm)
f5big-ip_access_policy_manager
f5big-ip_advanced_firewall_manager
f5big-ip_analytics
f5big-ip_application_acceleration_manager
f5big-ip_application_security_manager
f5big-ip_domain_name_system
f5big-ip_link_controller
f5big-ip_local_traffic_manager
f5big-ip_policy_enforcement_manager
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vulncheck8.1HIGH