CVE-2015-0235

Published Jan 28, 2015

Last updated a month ago

Overview

Description
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
Source
secalert@redhat.com
NVD status
Modified
Products
glibc, communications_application_session_controller, communications_eagle_application_processor, communications_eagle_lnp_application_processor, communications_lsms, communications_policy_management, communications_session_border_controller, communications_user_data_repository, communications_webrtc_session_controller, exalogic_infrastructure, vm_virtualbox, linux, debian_linux, virtualization, mac_os_x, pureapplication_system, security_access_manager_for_enterprise_single_sign-on, php

Risk scores

CVSS 2.0

Type
Primary
Base score
10
Impact score
10
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-787

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.