Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-7547

EPSS 93.95% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-7547

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
GNU C Library 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GNU C Library(glibc,libc6)是一种按照LGPL许可协议发布的开源免费的C语言编译程序。 GNU C Library 2.23之前版本存在缓冲区错误漏洞。攻击者利用该漏洞导致系统拒绝服务(崩溃)或通过特制的DNS响应触发任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-7547

#POC DescriptionSource LinkShenlong Link
1Proof of concept for CVE-2015-7547https://github.com/fjserna/CVE-2015-7547POC Details
2test script for CVE-2015-7547https://github.com/cakuzo/CVE-2015-7547POC Details
3Nonehttps://github.com/t0r0t0r0/CVE-2015-7547POC Details
4glibc check and update in light of CVE-2015-7547https://github.com/rexifiles/rex-sec-glibcPOC Details
5 glibc getaddrinfo stack-based buffer overflowhttps://github.com/babykillerblack/CVE-2015-7547POC Details
6PoC exploit server for CVE-2015-7547https://github.com/jgajek/cve-2015-7547POC Details
7PoC attack server for CVE-2015-7547 buffer overflow vulnerability in glibc DNS stub resolver (public version)https://github.com/eSentire/cve-2015-7547-publicPOC Details
8Nonehttps://github.com/bluebluelan/CVE-2015-7547-proj-masterPOC Details
9loudonghttps://github.com/miracle03/CVE-2015-7547-masterPOC Details
10CVE-2015-7547 initial research.https://github.com/Stick-U235/CVE-2015-7547-ResearchPOC Details
11Glibc-Vulnerability-Exploit-CVE-2015-7547https://github.com/Amilaperera12/Glibc-Vulnerability-Exploit-CVE-2015-7547POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-7547

登录查看更多情报信息。

Same Patch Batch · n/a · 2016-02-18 · 14 CVEs total

CVE-2015-8286Zhuhai RaySharp固件安全漏洞
CVE-2015-8287Swann SRNVW-470LCD和SWNVW-470CAM 安全漏洞
CVE-2016-0794LibreOffice 缓冲区错误漏洞
CVE-2016-0795LibreOffice 缓冲区错误漏洞
CVE-2015-5970Novell ZENworks Configuration Management 安全漏洞
CVE-2015-8148Symantec Encryption Management Server LDAP服务安全漏洞
CVE-2015-8149Symantec Encryption Management Server LDAP服务拒绝服务
CVE-2015-8150Symantec Encryption Management Server 安全漏洞
CVE-2015-8151Symantec Encryption Management Server 安全漏洞
CVE-2016-0068Microsoft Internet Explorer 特权提升漏洞
CVE-2016-0069Microsoft Internet Explorer 特权提升漏洞
CVE-2016-1987HPE IPFilter 拒绝服务漏洞
CVE-2016-2509Belden Hirschmann Classic Platform 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2015-7547

No comments yet


Leave a comment