Vulnerability CVE-2015-1781: Information

Description

Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.

Severity: MEDIUM (6.8)

Published: Sept. 28, 2015
Modified: Feb. 13, 2023
Error type identifier: CWE-119

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://sourceware.org/bugzilla/show_bug.cgi?id=18287
  • Issue Tracking
  • Third Party Advisory
[libc-alpha] 20150814 The GNU C Library version 2.22 is now available
  • Mailing List
  • Third Party Advisory
SUSE-SU-2015:1424
  • Mailing List
  • Third Party Advisory
RHSA-2015:0863
  • Third Party Advisory
74255
  • Third Party Advisory
  • VDB Entry
SUSE-SU-2016:0470
  • Mailing List
  • Third Party Advisory
USN-2985-2
  • Third Party Advisory
USN-2985-1
  • Third Party Advisory
GLSA-201602-02
  • Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
  • Third Party Advisory
1032178
  • Third Party Advisory
  • VDB Entry
DSA-3480
  • Third Party Advisory
FEDORA-2016-0480defc94
  • Mailing List
  • Third Party Advisory
https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=2959eda9272a03386
      1. Configuration 1

        cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*

        cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*

        cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp3:*:*:*:*:*:*

        cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*

        cpe:2.3:o:suse:linux_enterprise_desktop:11:sp4:*:*:*:*:*:*

        cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:*:*:*

        cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*

        Configuration 2

        cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*
        End including
        2.21

        Configuration 3

        cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

        Configuration 4

        cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*

        cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

        cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*