Out-of-bounds write in GNU C Library (glibc) - CVE-2015-0235

 

Out-of-bounds write in GNU C Library (glibc) - CVE-2015-0235

Published: December 28, 2023


Vulnerability identifier: #VU84832
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-0235
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc. A remote attacker can execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function.


Affected software

GNU C Library (glibc)
Gentoo Linux
Slackware Linux
Fedora
Hyper-Scale Manager
XIV Storage System Gen2
XIV Storage System Gen 3.0
glibc
glibc-solibs
glibc-i18n
glibc-profile
sys-libs/glibc
php

How to mitigate CVE-2015-0235

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

GNU C Library (glibc) - update to 2.18
Hyper-Scale Manager - update to 1.5.1.33
glibc - addressed in versions 2.9, 2.11.1, 2.13, 2.15, 2.17
glibc-solibs - addressed in versions 2.9, 2.11.1, 2.13, 2.15, 2.17
glibc-i18n - addressed in versions 2.9, 2.11.1, 2.13, 2.15, 2.17
glibc-profile - addressed in versions 2.9, 2.11.1, 2.13, 2.15, 2.17
sys-libs/glibc - update to 2.19-r1
php - update to 5.6.6-1.fc21
XIV Storage System Gen2 - update to 10.2.4.e-7
XIV Storage System Gen 3.0 - addressed in versions 11.4.2.c, 11.5.1.a

External References

Related Security Bulletins