CVE-2015-0235

critical
Published 2015-01-28 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
10.0

Description

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-36421 remote linux verified
Qualys Corporation ยท 2015-03-18

Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)

Source code queued for fetch โ€” refresh in a moment.
EDB-35951 dos linux
1n3 ยท 2015-01-29

Exim ESMTP 4.80 - glibc gethostbyname Denial of Service

Source code queued for fetch โ€” refresh in a moment.

Metasploit modules

WordPress XMLRPC GHOST Vulnerability Scanner
Source code queued for fetch โ€” refresh in a moment.
Exim GHOST (glibc gethostbyname) Buffer Overflow
Source fetch failed: fetch_error โ€” view the original via the link above.

OS impact

macos macOS Affected 1 release
VersionStatusFixed in
โ€” Affected 10.11.1
debian Debian Mixed 7 releases
VersionStatusFixed in
trixie Fixed 2.18-1
sid Fixed 2.18-1
forky Fixed 2.18-1
bullseye Fixed 2.18-1
bookworm Fixed 2.18-1
8.0 Affected โ€”
7.0 Affected โ€”

Application impact

VendorProductVersionsFixed
gnuglibc{"startIncluding":"2.0","endExcluding":"2.18"}2.18
oracle oraclecommunications_application_session_controller{"endExcluding":"3.7.1"}3.7.1
oracle oraclecommunications_eagle_application_processor16.0
oracle oraclecommunications_eagle_lnp_application_processor10.0
oracle oraclecommunications_lsms13.1
oracle oraclecommunications_policy_management9.7.3
oracle oraclecommunications_policy_management9.9.1
oracle oraclecommunications_policy_management10.4.1
oracle oraclecommunications_policy_management11.5
oracle oraclecommunications_policy_management12.1.1
oracle oraclecommunications_session_border_controller{"endExcluding":"7.2.0"}7.2.0
oracle oraclecommunications_session_border_controller7.2.0
oracle oraclecommunications_session_border_controller8.0.0
oracle oraclecommunications_user_data_repository{"startIncluding":"10.0.0","endIncluding":"10.0.1"}
oracle oraclecommunications_webrtc_session_controller7.0
oracle oraclecommunications_webrtc_session_controller7.1
oracle oraclecommunications_webrtc_session_controller7.2
oracle oracleexalogic_infrastructure1.0
oracle oracleexalogic_infrastructure2.0
oracle oraclevm_virtualbox{"endExcluding":"5.1.24"}5.1.24
redhat redhatvirtualization6.0
ibm ibmpureapplication_system1.0.0.0
ibm ibmpureapplication_system1.1.0.0
ibm ibmpureapplication_system2.0.0.0
ibm ibmsecurity_access_manager_for_enterprise_single_sign-on8.2
php phpphp{"startIncluding":"5.4.0","endExcluding":"5.4.38"}5.4.38

References

CWEs

CWE-787

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.