CVE-2015-7547 is a critical stack-based buffer overflow vulnerability in the glibc library's send_dg and send_vc functions, affecting numerous products from vendors like Canonical, Debian, Red Hat, and SUSE. With a CVSS score of 8.1 (HIGH), it allows remote attackers to cause denial of service or potentially execute arbitrary code via crafted DNS responses, requiring high attack complexity but no user interaction. While not listed on the KEV catalog, exploit code is publicly available on ExploitDB, and it has garnered significant community discussion and media coverage, indicating a high level of awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
15.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* | ||
1.1.1CPE matchmatch criteria | cpe:2.3:a:hp:helion_openstack:1.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Portable SDK for UPnP Devices (libupnp) glibc Implementation getaddrinfo() Function Remote Stack Overflow
Jan 27, 2017[R1] Portable SDK for UPnP Devices (libupnp) glibc Implementation getaddrinfo() Function Remote Stack Overflow
Jan 27, 2017[R1] Portable SDK for UPnP Devices (libupnp) glibc Implementation getaddrinfo() Function Remote Stack Overflow
Jan 26, 2017[R1] Portable SDK for UPnP Devices (libupnp) glibc Implementation getaddrinfo() Function Remote Stack Overflow
Jan 26, 2017glibc: getaddrinfo stack-based buffer overflow
Feb 16, 2016glibc getaddrinfo stack-based buffer overflow
Feb 9, 2016