Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-1781

Опубликовано: 28 сент. 2015
Источник: debian
EPSS Низкий

Описание

Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.21-0experimental1experimentalpackage
glibcfixed2.19-20package
glibcfixed2.19-18+deb8u1jessiepackage
eglibcremovedpackage

Примечания

  • https://sourceware.org/bugzilla/show_bug.cgi?id=18287

  • Upstream commit: https://sourceware.org/git/?p=glibc.git;a=commit;h=2959eda9272a03386

EPSS

Процентиль: 89%
0.05081
Низкий

Связанные уязвимости

ubuntu
почти 10 лет назад

Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.

redhat
больше 10 лет назад

Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.

nvd
почти 10 лет назад

Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.

github
больше 3 лет назад

Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.

suse-cvrf
почти 10 лет назад

Security update for glibc

EPSS

Процентиль: 89%
0.05081
Низкий