CVE-2015-7547

HIGH EXPLOITED

GNU C Library <2.23 - Buffer Overflow

Title source: llm

Description

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

Exploits (15)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdoslinux
https://www.exploit-db.com/exploits/39454
exploitdb WORKING POC
by SpeeDr00t · pythonremotelinux
https://www.exploit-db.com/exploits/40339
nomisec WORKING POC 546 stars
by fjserna · dos
https://github.com/fjserna/CVE-2015-7547
github WORKING POC 31 stars
by OpenSISE · cpoc
https://github.com/OpenSISE/CVE_PoC_Collect/tree/master/RCE/android/CVE-2015-7547
nomisec WORKING POC 10 stars
by eSentire · dos
https://github.com/eSentire/cve-2015-7547-public
nomisec WORKING POC 8 stars
by jgajek · remote
https://github.com/jgajek/cve-2015-7547
nomisec SCANNER 5 stars
by cakuzo · poc
https://github.com/cakuzo/CVE-2015-7547
nomisec WORKING POC 1 stars
by t0r0t0r0 · poc
https://github.com/t0r0t0r0/CVE-2015-7547
nomisec WORKING POC
by Stick-U235 · dos
https://github.com/Stick-U235/CVE-2015-7547-Research
nomisec STUB
by Amilaperera12 · poc
https://github.com/Amilaperera12/Glibc-Vulnerability-Exploit-CVE-2015-7547
nomisec WORKING POC
by miracle03 · dos
https://github.com/miracle03/CVE-2015-7547-master
nomisec WORKING POC
by bluebluelan · dos
https://github.com/bluebluelan/CVE-2015-7547-proj-master
nomisec WORKING POC
by babykillerblack · dos
https://github.com/babykillerblack/CVE-2015-7547
nomisec STUB
by rexifiles · poc
https://github.com/rexifiles/rex-sec-glibc

References (75)

... and 55 more

Scores

CVSS v3 8.1
EPSS 0.9395
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2021-08-17
CWE
CWE-119
Status published
Products (50)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 15.10
debian/debian_linux 8.0
f5/big-ip_access_policy_manager 12.0.0
f5/big-ip_advanced_firewall_manager 12.0.0
f5/big-ip_analytics 12.0.0
f5/big-ip_application_acceleration_manager 12.0.0
f5/big-ip_application_security_manager 12.0.0
f5/big-ip_domain_name_system 12.0.0
... and 40 more
Published Feb 18, 2016
Tracked Since Feb 18, 2026