PublicDateAtUSN: 2016-02-16 14:00:00 UTC Candidate: CVE-2015-7547 CRD: 2016-02-16 14:00:00 UTC PublicDate: 2016-02-18 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7547 https://sourceware.org/ml/libc-alpha/2016-02/msg00416.html https://googleonlinesecurity.blogspot.com/2016/02/cve-2015-7547-glibc-getaddrinfo-stack.html https://ubuntu.com/security/notices/USN-2900-1 Description: Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module. Ubuntu-Description: Notes: jdstrand> stable-phone-overlay will be updated in OTA 9.1 jdstrand> tyhicks alerted the Snappy team for an emergency update Bugs: https://sourceware.org/bugzilla/show_bug.cgi?id=18665 Priority: high Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_eglibc: upstream_eglibc: needs-triage precise_eglibc: released (2.15-0ubuntu10.13) trusty_eglibc: released (2.19-0ubuntu6.7) trusty/esm_eglibc: released (2.19-0ubuntu6.7) vivid_eglibc: DNE vivid/ubuntu-core_eglibc: DNE vivid/stable-phone-overlay_eglibc: DNE wily_eglibc: DNE devel_eglibc: DNE Patches_glibc: upstream_glibc: needs-triage precise_glibc: DNE trusty_glibc: DNE trusty/esm_glibc: DNE vivid_glibc: ignored (reached end-of-life) vivid/ubuntu-core_glibc: released (2.21-0ubuntu4.0.1) vivid/stable-phone-overlay_glibc: released (2.21-0ubuntu4.0.1) wily_glibc: released (2.21-0ubuntu4.1) devel_glibc: released (2.21-0ubuntu6)