ISOMAN

CVE

CVE-2015-7547

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

Severity
HIGH
CVSS
8.1
Published
Modified

Linked Releases

References

  1. http://fortiguard.com/advisory/glibc-getaddrinfo-stack-overflow
  2. http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177404.html
  3. http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177412.html
  4. http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html
  5. http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.html
  6. http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.html
  7. http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.html
  8. http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00042.html
  9. http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00043.html
  10. http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00044.html
  11. http://marc.info/?l=bugtraq&m=145596041017029&w=2
  12. http://marc.info/?l=bugtraq&m=145672440608228&w=2
  13. http://marc.info/?l=bugtraq&m=145690841819314&w=2
  14. http://marc.info/?l=bugtraq&m=145857691004892&w=2
  15. http://marc.info/?l=bugtraq&m=146161017210491&w=2
  16. http://packetstormsecurity.com/files/135802/glibc-getaddrinfo-Stack-Based-Buffer-Overflow.html
  17. http://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html
  18. http://packetstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.html
  19. http://packetstormsecurity.com/files/167552/Nexans-FTTO-GigaSwitch-Outdated-Components-Hardcoded-Backdoor.html
  20. http://rhn.redhat.com/errata/RHSA-2016-0175.html