UBUNTU-CVE-2015-7547
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-7547
UBUNTU-CVE-2015-7547
Summary:
Details: Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
References: https://ubuntu.com/security/CVE-2015-7547, https://sourceware.org/ml/libc-alpha/2016-02/msg00416.html, https://googleonlinesecurity.blogspot.com/2016/02/cve-2015-7547-glibc-getaddrinfo-stack.html, https://ubuntu.com/security/notices/USN-2900-1, https://www.cve.org/CVERecord?id=CVE-2015-7547
Affected packages
Package
Name: eglibc
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
