peter bassill · operator
$ cve CVE-2015-7547 JSON

CVE-2015-7547 EXPLOIT

8.1
HIGH · CVSS 3.0 · EPSS 91% (pctl 100)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

Scoring

CVSS8.1 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS90.99% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2016-02-18
Last modified2026-06-17

Affected (30)

VendorProduct
canonicalubuntu linux
debiandebian linux
f5big-ip access policy manager
f5big-ip advanced firewall manager
f5big-ip analytics
f5big-ip application acceleration manager
f5big-ip application security manager
f5big-ip domain name system
f5big-ip link controller
f5big-ip local traffic manager
f5big-ip policy enforcement manager
gnuglibc
hphelion openstack
hpserver migration pack
opensuseopensuse
oracleexalogic infrastructure
oraclefujitsu m10 firmware
redhatenterprise linux desktop
redhatenterprise linux hpc node
redhatenterprise linux hpc node eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux workstation
sophosunified threat management software
suselinux enterprise debuginfo
suselinux enterprise desktop
suselinux enterprise server
suselinux enterprise software development kit
susesuse linux enterprise server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD