CVE-2015-7547 — Red Hat
HIGHCVE-2015-7547 is a high-severity (CVSS 8.1) Buffer Overflow vulnerability. 10 public exploit references exist, so weaponization risk is real. No vendor fix is recorded yet; mitigation options are listed below.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2015-7547 by exploitation likelihood (EPSS) against impact (CVSS). In the shaded patch-first corner (EPSS 50%+, CVSS 7.0+).
Where this sits among everything scored
Of 384,534 CVEs with a current EPSS score, this one falls in the ≥ 90% band (highlighted). Counts from FIRST.org, log-scaled.
Description
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
Affected Products
ubuntu linuxcanonicaldebian linuxdebianbig-ip access policy managerf5big-ip advanced firewall managerf5big-ip analyticsf5big-ip application acceleration managerf5Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
glibc - 'getaddrinfo' Stack Buffer Overflow (PoC)
by Google Security Research · Feb 16, 2016
glibc - 'getaddrinfo' Remote Stack Buffer Overflow
by SpeeDr00t · Sep 6, 2016
Detection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Remediation status
No fixed release is recorded for CVE-2015-7547 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.
Mitigate without a patch
Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
After updating the glibc package on affected systems, it is strongly recommended to reboot the system or restart all the affected services. For more information please refer to: https://access.redhat.com/articles/2161461
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Enterprise Linux 6 | glibc-0:2.12-1.166.el6_7.7 | RHSA-2016:0175 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | glibc-0:2.12-1.47.el6_2.17 | RHSA-2016:0225 |
| Red Hat Enterprise Linux 7 | glibc-0:2.17-106.el7_2.4 | RHSA-2016:0176 |
| RHEV 3.X Hypervisor and Agents for RHEL-6 | rhev-hypervisor6-0:6.7-20160104.2.el6ev | RHSA-2016:0277 |
Frequently Asked Questions
Is CVE-2015-7547 in your dependencies?
Find it across , including transitive dependencies.