HIGH · 8.1

CVE-2015-7547

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a deni...

Vulnerability Description

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

CVSS Score

8.1

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DebianDebian Linux8.0
CanonicalUbuntu Linux12.04
HpHelion Openstack1.1.1
HpServer Migration Pack7.5
SophosUnified Threat Management Software9.319
SuseLinux Enterprise Debuginfo11.0
OpensuseOpensuse13.2
SuseLinux Enterprise Desktop11.0
SuseLinux Enterprise Server11.0
SuseLinux Enterprise Software Development Kit11.0
SuseSuse Linux Enterprise Server12
OracleExalogic Infrastructure1.0
F5Big-Ip Access Policy Manager12.0.0
F5Big-Ip Advanced Firewall Manager12.0.0
F5Big-Ip Analytics12.0.0
F5Big-Ip Application Acceleration Manager12.0.0
F5Big-Ip Application Security Manager12.0.0
F5Big-Ip Domain Name System12.0.0
F5Big-Ip Link Controller12.0.0
F5Big-Ip Local Traffic Manager12.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-7547?

CVE-2015-7547 is a vulnerability with a CVSS score of 8.1 (HIGH). Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a deni...

How severe is CVE-2015-7547?

CVE-2015-7547 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-7547?

Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Canonical Ubuntu Linux, Hp Helion Openstack, Hp Server Migration Pack, Sophos Unified Threat Management Software.