CVE-2015-7547
75Vexday Risk Score
Priorize a correção. Ela exploração observada pelo VulnCheck e tem prova de conceito pública.
ssvc Actepss 90%
da publicação à arma0 dias
Publicada no NVD18 de fev.
1ª PoC10 de fev.
VulnCheck+2007d
probabilidade de exploração
90%top 1% das CVEs
exploração observada
simVulnCheck
29 exploit(s) público(s)
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 29✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39454exploitdbwww.exploit-db.com/exploits/40339não verificadogithubgithub.com/fjserna/CVE-2015-7547★ 543githubgithub.com/eSentire/cve-2015-7547-public★ 10githubgithub.com/jgajek/cve-2015-7547★ 8githubgithub.com/cakuzo/CVE-2015-7547★ 5githubgithub.com/t0r0t0r0/CVE-2015-7547★ 1githubgithub.com/Stick-U235/CVE-2015-7547-Research★ 0githubgithub.com/Amilaperera12/Glibc-Vulnerability-Exploit-CVE-2015-7547★ 0githubgithub.com/miracle03/CVE-2015-7547-master★ 0githubgithub.com/babykillerblack/CVE-2015-7547★ 0githubgithub.com/bluebluelan/CVE-2015-7547-proj-master★ 0githubgithub.com/rexifiles/rex-sec-glibc★ 0cve_referencepacketstormsecurity.com/files/167552/Nexans-FTTO-GigaSwitch-Outdated-Components-Hardcoded-Backdoor.htmlnão verificadovulncheckvulncheck.com/xdb/5802082611f4não verificadocve_referencewww.exploit-db.com/exploits/40339/não verificadocve_referencewww.exploit-db.com/exploits/39454/não verificadovulncheckvulncheck.com/xdb/048e7854f0canão verificadovulncheckvulncheck.com/xdb/9aca57789b8bnão verificadovulncheckvulncheck.com/xdb/b99728f6c6e2não verificadovulncheckvulncheck.com/xdb/e789fb086b1fnão verificadovulncheckvulncheck.com/xdb/a972b421d0c1não verificadovulncheckvulncheck.com/xdb/6ca51ee2343enão verificadovulncheckvulncheck.com/xdb/1dc3a463272enão verificadovulncheckvulncheck.com/xdb/356972add841não verificadovulncheckvulncheck.com/xdb/bb7c175544abnão verificadocve_referencepacketstormsecurity.com/files/135802/glibc-getaddrinfo-Stack-Based-Buffer-Overflow.htmlnão verificadocve_referencepacketstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlnão verificadocve_referencepacketstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.htmlnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
http://fortiguard.com/advisory/glibc-getaddrinfo-stack-overflowhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177404.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177412.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00044.htmlhttp://marc.info/?l=bugtraq&m=145596041017029&w=2http://marc.info/?l=bugtraq&m=145672440608228&w=2