Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2015-0235

Quick assessment

Affected
n/a n/a
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GNU glibc(又名GNU C Library,libc6)是一种按照LGPL许可协议发布的开源免费的C语言编译程序。 GNU glibc 2.2版本和2.18之前2.x版本中的‘__nss_hostname_digits_dots’函数存在基于堆的缓冲区溢出漏洞。本地和远程攻击者都可通过调用‘ gethostbyname*()’函数利用该漏洞以运行应用程序的用户权限执行任意代码,控制系统。

AI Predicted 9.8 Difficulty: Easy EPSS 94.56% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2015-0235

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
GNU glibc 基于堆的缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GNU glibc(又名GNU C Library,libc6)是一种按照LGPL许可协议发布的开源免费的C语言编译程序。 GNU glibc 2.2版本和2.18之前2.x版本中的‘__nss_hostname_digits_dots’函数存在基于堆的缓冲区溢出漏洞。本地和远程攻击者都可通过调用‘ gethostbyname*()’函数利用该漏洞以运行应用程序的用户权限执行任意代码,控制系统。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2015-0235

# POC Description Source Link Shenlong Link
1 Test wether you're exposed to ghost (CVE-2015-0235). All kudos go to Qualys Security https://github.com/fser/ghost-checker POC Details
2 A chef cookbook to test the GHOST vulnerability https://github.com/mikesplain/CVE-2015-0235-cookbook POC Details
3 Ansible playbook to check vulnerability for CVE-2015-0235 https://github.com/aaronfay/CVE-2015-0235-test POC Details
4 glibc vulnerability GHOST(CVE-2015-0235) Affected software list https://github.com/piyokango/ghost POC Details
5 None https://github.com/mholzinger/CVE-2015-0235_GHOST POC Details
6 Ansible playbook, to check for CVE-2015-0235 (GHOST) vulnerability https://github.com/adherzog/ansible-CVE-2015-0235-GHOST POC Details
7 CVE-2015-0235 patches lenny libc6 packages for amd64 https://github.com/favoretti/lenny-libc6 POC Details
8 gethostbyname*() buffer overflow exploit in glibc - CVE-2015-0235 https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability https://github.com/nickanderson/cfengine-CVE_2015_0235 POC Details
9 cookbook for update glibc. CVE-2015-0235(GHOST) https://github.com/koudaiii-archives/cookbook-update-glibc POC Details
10 Playbooks 'Fix for CVE-2015-0235(GHOST)' running on Ansible https://github.com/F88/ghostbusters15 POC Details
11 glibc gethostbyname bug https://github.com/tobyzxj/CVE-2015-0235 POC Details
12 A shared library wrapper with additional checks for vulnerable functions gethostbyname2_r gethostbyname_r (GHOST vulnerability) https://github.com/makelinux/CVE-2015-0235-workaround POC Details
13 CVE-2015-0235 EXIM ESTMP GHOST Glibc Gethostbyname() DoS Exploit/PoC https://github.com/arm13/ghost_exploit POC Details
14 CVE-2015-0235 https://github.com/alanmeyer/CVE-glibc POC Details
15 Script to test vulnarability for CVE-2015-0235 https://github.com/1and1-serversupport/ghosttester POC Details
16 None https://github.com/sUbc0ol/CVE-2015-0235 POC Details
17 A check for GHOST; cve-2015-0235 https://github.com/chayim/GHOSTCHECK-cve-2015-0235 POC Details
18 None https://github.com/limkokholefork/GHOSTCHECK-cve-2015-0235 POC Details
19 None https://github.com/furyutei/CVE-2015-0235_GHOST POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-0235

登录查看更多情报信息。

Vendor Advisories for CVE-2015-0235 (54)

Exploits & Public PoCs for CVE-2015-0235 (6)

Mailing List Discussions for CVE-2015-0235 (15)

Other References for CVE-2015-0235 (13)

Same Patch Batch · n/a · 2015-01-28 · 9 CVEs total

CVE-2014-8917 IBM Social Media Analytics 跨站脚本漏洞
CVE-2014-8920 IBM i Access 5770-XE1 Data Transfer Program 缓冲区溢出漏洞
CVE-2015-0312 Adobe Flash Player 双重释放漏洞
CVE-2015-0581 Cisco Prime Service Catalog 安全漏洞
CVE-2015-0586 Cisco 2900 Series Integrated Services Router 拒绝服务漏洞
CVE-2015-1375 WordPress Pixabay Images插件权限许可和访问控制漏洞
CVE-2015-1376 WordPress Pixabay Images插件输入验证漏洞
CVE-2015-1419 VSFTP 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2015-0235

No comments yet


Leave a comment