CVE-2015-0235
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers...
- Published
- Jan 28, 2015
- Updated
- Aug 6, 2024
- Assigning CNA
- redhat
- Evidence observed
- Jan 29, 2015
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:CHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
Sources
12- CVE-glibcDetection
CVE-2015-0235
- ghost-checkerScanner
Test wether you're exposed to ghost (CVE-2015-0235). All kudos go to Qualys Security
A shared library wrapper with additional checks for vulnerable functions gethostbyname2_r gethostbyname_r (GHOST vulnerability)
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.