CVE-2015-0235

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
28/01/2015
Last modified:
12/04/2025

Description

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* 2.0 (including) 2.18 (excluding)
cpe:2.3:a:oracle:communications_application_session_controller:*:*:*:*:*:*:*:* 3.7.1 (excluding)
cpe:2.3:a:oracle:communications_eagle_application_processor:16.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:10.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_lsms:13.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_policy_management:9.7.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_policy_management:9.9.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_policy_management:10.4.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_policy_management:11.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_policy_management:12.1.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_session_border_controller:*:*:*:*:*:*:*:* 7.2.0 (excluding)
cpe:2.3:a:oracle:communications_session_border_controller:7.2.0:-:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_session_border_controller:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_user_data_repository:*:*:*:*:*:*:*:* 10.0.0 (including) 10.0.1 (including)
cpe:2.3:a:oracle:communications_webrtc_session_controller:7.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools