8.1

CVE-2015-7547

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

Data is provided by the National Vulnerability Database (NVD)
DebianDebian Linux Version8.0
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version15.10
HpHelion Openstack Version1.1.1
HpHelion Openstack Version2.0.0
HpHelion Openstack Version2.1.0
HpServer Migration Pack Version7.5
SuseLinux Enterprise Debuginfo Version11.0 Updatesp2
SuseLinux Enterprise Debuginfo Version11.0 Updatesp3
SuseLinux Enterprise Debuginfo Version11.0 Updatesp4
OpensuseOpensuse Version13.2
SuseLinux Enterprise Desktop Version11.0 Updatesp3
SuseLinux Enterprise Desktop Version11.0 Updatesp4
SuseLinux Enterprise Desktop Version12 Updatesp1
SuseLinux Enterprise Server Version11.0 Updatesp2 SwEditionlts
SuseLinux Enterprise Server Version11.0 Updatesp3
SuseLinux Enterprise Server Version11.0 Updatesp3 SwPlatformvmware
SuseLinux Enterprise Server Version11.0 Updatesp4
SuseLinux Enterprise Server Version12 Updatesp1
F5Big-ip Access Policy Manager Version12.0.0
F5Big-ip Analytics Version12.0.0
F5Big-ip Domain Name System Version12.0.0
F5Big-ip Link Controller Version12.0.0
F5Big-ip Local Traffic Manager Version12.0.0
OracleFujitsu M10 Firmware Version <= 2290
GnuGlibc Version2.9
GnuGlibc Version2.10
GnuGlibc Version2.10.1
GnuGlibc Version2.11
GnuGlibc Version2.11.1
GnuGlibc Version2.11.2
GnuGlibc Version2.11.3
GnuGlibc Version2.12
GnuGlibc Version2.12.1
GnuGlibc Version2.12.2
GnuGlibc Version2.13
GnuGlibc Version2.14
GnuGlibc Version2.14.1
GnuGlibc Version2.15
GnuGlibc Version2.16
GnuGlibc Version2.17
GnuGlibc Version2.18
GnuGlibc Version2.19
GnuGlibc Version2.20
GnuGlibc Version2.21
GnuGlibc Version2.22
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 93.42% 0.998
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://ubuntu.com/usn/usn-2900-1
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1293532
Third Party Advisory
Issue Tracking