Rapid7 Vulnerability & Exploit Database

SUSE: CVE-2015-0235: SUSE Linux Security Advisory

Back to Search

SUSE: CVE-2015-0235: SUSE Linux Security Advisory

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
01/28/2015
Created
07/25/2018
Added
12/18/2015
Modified
02/04/2022

Description

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

Solution(s)

  • suse-upgrade-apache2-mod_php7
  • suse-upgrade-glibc
  • suse-upgrade-glibc-32bit
  • suse-upgrade-glibc-devel
  • suse-upgrade-glibc-devel-32bit
  • suse-upgrade-glibc-html
  • suse-upgrade-glibc-i18ndata
  • suse-upgrade-glibc-info
  • suse-upgrade-glibc-locale
  • suse-upgrade-glibc-locale-32bit
  • suse-upgrade-glibc-locale-x86
  • suse-upgrade-glibc-profile
  • suse-upgrade-glibc-profile-32bit
  • suse-upgrade-glibc-profile-x86
  • suse-upgrade-glibc-x86
  • suse-upgrade-libxcrypt
  • suse-upgrade-libxcrypt-32bit
  • suse-upgrade-nscd
  • suse-upgrade-pam-modules
  • suse-upgrade-pam-modules-32bit
  • suse-upgrade-php7
  • suse-upgrade-php7-bcmath
  • suse-upgrade-php7-bz2
  • suse-upgrade-php7-calendar
  • suse-upgrade-php7-ctype
  • suse-upgrade-php7-curl
  • suse-upgrade-php7-dba
  • suse-upgrade-php7-devel
  • suse-upgrade-php7-dom
  • suse-upgrade-php7-embed
  • suse-upgrade-php7-enchant
  • suse-upgrade-php7-exif
  • suse-upgrade-php7-fastcgi
  • suse-upgrade-php7-fileinfo
  • suse-upgrade-php7-fpm
  • suse-upgrade-php7-ftp
  • suse-upgrade-php7-gd
  • suse-upgrade-php7-gettext
  • suse-upgrade-php7-gmp
  • suse-upgrade-php7-iconv
  • suse-upgrade-php7-imap
  • suse-upgrade-php7-intl
  • suse-upgrade-php7-json
  • suse-upgrade-php7-ldap
  • suse-upgrade-php7-mbstring
  • suse-upgrade-php7-mcrypt
  • suse-upgrade-php7-mysql
  • suse-upgrade-php7-odbc
  • suse-upgrade-php7-opcache
  • suse-upgrade-php7-openssl
  • suse-upgrade-php7-pcntl
  • suse-upgrade-php7-pdo
  • suse-upgrade-php7-pear
  • suse-upgrade-php7-pear-archive_tar
  • suse-upgrade-php7-pgsql
  • suse-upgrade-php7-phar
  • suse-upgrade-php7-posix
  • suse-upgrade-php7-pspell
  • suse-upgrade-php7-readline
  • suse-upgrade-php7-shmop
  • suse-upgrade-php7-snmp
  • suse-upgrade-php7-soap
  • suse-upgrade-php7-sockets
  • suse-upgrade-php7-sodium
  • suse-upgrade-php7-sqlite
  • suse-upgrade-php7-sysvmsg
  • suse-upgrade-php7-sysvsem
  • suse-upgrade-php7-sysvshm
  • suse-upgrade-php7-tidy
  • suse-upgrade-php7-tokenizer
  • suse-upgrade-php7-wddx
  • suse-upgrade-php7-xmlreader
  • suse-upgrade-php7-xmlrpc
  • suse-upgrade-php7-xmlwriter
  • suse-upgrade-php7-xsl
  • suse-upgrade-php7-zip
  • suse-upgrade-php7-zlib
  • suse-upgrade-php72-devel
  • suse-upgrade-pwdutils
  • suse-upgrade-pwdutils-plugin-audit

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;