CVE-2015-0235 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 94.6% (pctl 100)
Patch early
A public exploit exists.
Description
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 94.56% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-01-28 |
| Last modified | 2026-06-17 |
Affected (18)
| Vendor | Product |
|---|---|
| apple | mac os x |
| debian | debian linux |
| gnu | glibc |
| ibm | pureapplication system |
| ibm | security access manager for enterprise single sign-on |
| oracle | communications application session controller |
| oracle | communications eagle application processor |
| oracle | communications eagle lnp application processor |
| oracle | communications lsms |
| oracle | communications policy management |
| oracle | communications session border controller |
| oracle | communications user data repository |
| oracle | communications webrtc session controller |
| oracle | exalogic infrastructure |
| oracle | linux |
| oracle | vm virtualbox |
| php | php |
| redhat | virtualization |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit) | 2015-03-18 |
| exploit-db | Exim ESMTP 4.80 - glibc gethostbyname Denial of Service | 2015-01-29 |
References
- http://blogs.sophos.com/2015/01/29/sophos-products-and-the-ghost-vulnerability-affecting-linux/
- http://linux.oracle.com/errata/ELSA-2015-0090.html
- http://linux.oracle.com/errata/ELSA-2015-0092.html
- http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html
- http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
- http://marc.info/?l=bugtraq&m=142296726407499&w=2
- http://marc.info/?l=bugtraq&m=142721102728110&w=2
- http://marc.info/?l=bugtraq&m=142722450701342&w=2
- http://marc.info/?l=bugtraq&m=142781412222323&w=2
- http://marc.info/?l=bugtraq&m=143145428124857&w=2
- http://packetstormsecurity.com/files/130171/Exim-ESMTP-GHOST-Denial-Of-Service.html
- http://packetstormsecurity.com/files/130768/EMC-Secure-Remote-Services-GHOST-SQL-Injection-Command-Injection.html
- http://packetstormsecurity.com/files/130974/Exim-GHOST-glibc-gethostbyname-Buffer-Overflow.html
- http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.html
- http://packetstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.html
- http://packetstormsecurity.com/files/167552/Nexans-FTTO-GigaSwitch-Outdated-Components-Hardcoded-Backdoor.html
- http://rhn.redhat.com/errata/RHSA-2015-0126.html
- http://seclists.org/fulldisclosure/2015/Jan/111
- http://seclists.org/fulldisclosure/2019/Jun/18
→ the Explorer · watch your stack · NVD