CVE-2015-7547
75Vexday Risk Score
Prioriza la corrección. Ella explotación observada por VulnCheck y tiene prueba de concepto pública.
ssvc Actepss 90%
de la publicación al arma0 días
Publicada en NVD18 feb
1ª PoC10 feb
VulnCheck+2007d
probabilidad de explotación
90%top 1% de las CVE
explotación observada
síVulnCheck
29 exploit(s) público(s)
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
Productos afectados
n/a · n/aPoCs públicas encontradas — 29✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39454exploitdbwww.exploit-db.com/exploits/40339no verificadogithubgithub.com/fjserna/CVE-2015-7547★ 543githubgithub.com/eSentire/cve-2015-7547-public★ 10githubgithub.com/jgajek/cve-2015-7547★ 8githubgithub.com/cakuzo/CVE-2015-7547★ 5githubgithub.com/t0r0t0r0/CVE-2015-7547★ 1githubgithub.com/Stick-U235/CVE-2015-7547-Research★ 0githubgithub.com/Amilaperera12/Glibc-Vulnerability-Exploit-CVE-2015-7547★ 0githubgithub.com/miracle03/CVE-2015-7547-master★ 0githubgithub.com/babykillerblack/CVE-2015-7547★ 0githubgithub.com/bluebluelan/CVE-2015-7547-proj-master★ 0githubgithub.com/rexifiles/rex-sec-glibc★ 0cve_referencepacketstormsecurity.com/files/167552/Nexans-FTTO-GigaSwitch-Outdated-Components-Hardcoded-Backdoor.htmlno verificadovulncheckvulncheck.com/xdb/5802082611f4no verificadocve_referencewww.exploit-db.com/exploits/40339/no verificadocve_referencewww.exploit-db.com/exploits/39454/no verificadovulncheckvulncheck.com/xdb/048e7854f0cano verificadovulncheckvulncheck.com/xdb/9aca57789b8bno verificadovulncheckvulncheck.com/xdb/b99728f6c6e2no verificadovulncheckvulncheck.com/xdb/e789fb086b1fno verificadovulncheckvulncheck.com/xdb/a972b421d0c1no verificadovulncheckvulncheck.com/xdb/6ca51ee2343eno verificadovulncheckvulncheck.com/xdb/1dc3a463272eno verificadovulncheckvulncheck.com/xdb/356972add841no verificadovulncheckvulncheck.com/xdb/bb7c175544abno verificadocve_referencepacketstormsecurity.com/files/135802/glibc-getaddrinfo-Stack-Based-Buffer-Overflow.htmlno verificadocve_referencepacketstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlno verificadocve_referencepacketstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://fortiguard.com/advisory/glibc-getaddrinfo-stack-overflowhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177404.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177412.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00044.htmlhttp://marc.info/?l=bugtraq&m=145596041017029&w=2http://marc.info/?l=bugtraq&m=145672440608228&w=2