CVE-2015-7547

high
Published 2016-02-18 · Modified 2026-05-06
CVSS v3
8.1
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
6.8
VIR risk
8.1

Description

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

Predictions

Exploit likelihood
88%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-7547

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://sourceware.org/ml/libc-alpha/2016-02/msg00416.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.21-8
debian debianbullseyefixed2.21-8
debian debianforkyfixed2.21-8
debian debiansidfixed2.21-8
debian debiantrixiefixed2.21-8
debian debian8.0affected
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu15.10affected
suse suse13.2affected
suse suse11.0affected
suse suse12affected
redhat rhel7.0affected

Application impact

VendorProductVersionsFixed
hphelion_openstack1.1.1
hphelion_openstack2.0.0
hphelion_openstack2.1.0
hpserver_migration_pack7.5
sophosunified_threat_management_software9.319
sophosunified_threat_management_software9.355
suselinux_enterprise_debuginfo11.0
oracleexalogic_infrastructure1.0
oracleexalogic_infrastructure2.0
f5big-ip_access_policy_manager12.0.0
f5big-ip_advanced_firewall_manager12.0.0
f5big-ip_analytics12.0.0
f5big-ip_application_acceleration_manager12.0.0
f5big-ip_application_security_manager12.0.0
f5big-ip_domain_name_system12.0.0
f5big-ip_link_controller12.0.0
f5big-ip_local_traffic_manager12.0.0
f5big-ip_policy_enforcement_manager12.0.0
gnuglibc2.9
gnuglibc2.10
gnuglibc2.10.1
gnuglibc2.11
gnuglibc2.11.1
gnuglibc2.11.2
gnuglibc2.11.3
gnuglibc2.12
gnuglibc2.12.1
gnuglibc2.12.2
gnuglibc2.13
gnuglibc2.14
gnuglibc2.14.1
gnuglibc2.15
gnuglibc2.16
gnuglibc2.17
gnuglibc2.18
gnuglibc2.19
gnuglibc2.20
gnuglibc2.21
gnuglibc2.22

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.