CVE-2015-7547
HIGH 8.1EPSS 91.1%
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
- CVSS v3.0
- 8.1 HIGH
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 91.06% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2016-02-18
- Updated
- 2024-08-06
Proof-of-concept exploits (10)
- Amilaperera12/Glibc-Vulnerability-Exploit-CVE-2015-75470★ · 2020-05-12
- Stick-U235/CVE-2015-7547-Research0★ · 2022-10-29
- babykillerblack/CVE-2015-75470★ · 2016-02-21
- bluebluelan/CVE-2015-7547-proj-master0★ · 2016-11-11
- cakuzo/CVE-2015-75475★ · 2016-02-17
- eSentire/cve-2015-7547-public10★ · 2016-04-25
- fjserna/CVE-2015-7547543★ · 2016-02-20
- jgajek/cve-2015-75478★ · 2016-03-30
- miracle03/CVE-2015-7547-master0★ · 2019-06-04
- t0r0t0r0/CVE-2015-75471★ · 2016-02-22