ID

VAR-201501-0737


CVE

CVE-2015-0235


TITLE

GNU C Library (glibc) __nss_hostname_digits_dots() function vulnerable to buffer overflow

Trust: 0.8

sources: CERT/CC: VU#967332

DESCRIPTION

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST.". This vulnerability has been assigned CVE-2015-0235, and is referred to in the media by the name "GHOST". -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ESA-2015-040: EMC Secure Remote Services Virtual Edition Security Update for Multiple Vulnerabilities CVE Identifier: CVE-2015-0235, CVE-2015-0524, CVE-2015-0525 Severity Rating: CVSSv2 Base Score: See below for individual scores for each CVE Affected products: \x95 EMC Secure Remote Services Virtual Edition 3.02 \x95 EMC Secure Remote Services Virtual Edition 3.03 Summary: EMC Secure Remote Services Virtual Edition (ESRS VE) contains multiple vulnerabilities that may potentially be exploited by attackers to compromise the affected system. Details: \x95 GHOST Vulnerability (CVE-2015-0235) On January 27, 2015, a vulnerability was publicly announced in the Linux glibc library. The details for this vulnerability can be found using the link to Qualys Advisory https://www.qualys.com/research/security-advisories/GHOST-CVE-2015-0235.txt CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) \x95 SQL Injection (CVE-2015-0524) The ESRS VE Gateway Provisioning service contains a SQL injection vulnerability that could potentially be exploited by an attacker to retrieve arbitrary data from the application or interfere with its logic by executing arbitrary SQL commands on the affected system. CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) \x95 Command Injection (CVE-2015-0525) The ESRS VE Gateway Provisioning service contains a command injection vulnerability that could potentially be exploited by an attacker to execute arbitrary OS commands on the affected system. CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) Resolution: EMC recommends all customers upgrade to the following version at the earliest opportunity: \x95 EMC Secure Remote Services Virtual Edition 3.04 Link to remedies: Registered EMC Online Support customers can download patches and software from support.emc.com at: EMC Secure Remote Services -> EMC Secure Remote Services Virtual Edition -> Downloads If you have any questions, contact EMC Support. Credits: EMC would like to thank Han Sahin (han.sahin@securify.nl) of Securify B.V. (https://www.securify.nl) for reporting CVE-2015-0524 and CVE-2015-0525. Read and use the information in this EMC Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this product alert, contact EMC Software Technical Support at 1-877-534-2867. For an explanation of Severity Ratings, refer to EMC Knowledgebase solution emc218831. EMC recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply. References: CVE-2015-0235 SSRT102283 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. Please update or upgrade to one of the following versions or subsequent. - HP Mobility Software v6.4.3.0 - HP Mobility Software v6.5.3.0 The software updates are available by logging into "My Networking" portal at the following location: https://h10145.www1.hpe.com/sso/Index.aspx?ReturnUrl=..%2fdownloads%2fDow nloadSoftware.aspx%3fSoftwareReleaseUId%3d11068%26ProductNumber%3dJ9420A%26la ng%3d%26cc%3d%26prodSeriesId%3d HISTORY Version:1 (rev.1) - 2 November 2015 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running Hewlett-Packard Enterprise (HPE) software products should be applied in accordance with the customer's patch management policy. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hpe.com. 3C = 3COM 3P = 3rd Party Software GN = HPE General Software HF = HPE Hardware and Firmware MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PV = ProCurve ST = Storage Software UX = HP-UX Copyright 2015 Hewlett-Packard Enterprise Hewlett-Packard Enterprise shall not be liable for technical or editorial errors or omissions contained herein. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04589512 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04589512 Version: 1 HPSBGN03285 rev.1 - HP Business Service Manager Virtual Appliance, Multiple Vulnerabilities NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. Release Date: 2015-03-17 Last Updated: 2015-03-17 - ----------------------------------------------------------------------------- - --- Potential Security Impact: Multiple vulnerabilities Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY Potential security vulnerabilities have been identified with these three packages. These vulnerabilities could be exploited to allow execution of code. HP Operation Agent Virtual Appliance for monitoring VMware vSphere environments (OAVA) HP Virtualization Performance Viewer for monitoring VMware vSphere environments (vPV VA) HP Operations Manager i 10.00 Virtual (OMi VA) References: CVE-2015-0235 - Buffer Errors (CWE-119) CVE-2012-6657 - Permissions, Privileges, and Access Control (CWE-264) CVE-2014-3673 - Resource Management Errors (CWE-399) CVE-2014-3687 - Resource Management Errors (CWE-399) CVE-2014-3688 - Resource Management Errors (CWE-399) CVE-2014-5471 - Resource Management Errors (CWE-399) CVE-2014-5472 - Input Validation (CWE-20) CVE-2014-6410 - Resource Management Errors (CWE-399) CVE-2014-9322- Permissions, Privileges, and Access Control (CWE-264) SSRT101955 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. HP Operation Agent Virtual Appliance for monitoring VMware vSphere environments (OAVA) v11.14, v11.13, v11.12, v11.11 HP Virtualization Performance Viewer for monitoring VMware vSphere environments (vPV VA) v2.10, v2.01, v2.0, v1.x HP Operations Manager i 10.00 Virtual (OMi VA) v10.00 BACKGROUND For a PGP signed version of this security bulletin please write to: security-alert@hp.com CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2015-0235 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 CVE-2012-6657 (AV:L/AC:L/Au:N/C:N/I:N/A:C) 4.9 CVE-2014-3673 (AV:N/AC:L/Au:N/C:N/I:N/A:C) 7.8 CVE-2014-3687 (AV:N/AC:L/Au:N/C:N/I:N/A:C) 7.8 CVE-2014-3688 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 CVE-2014-5471 (AV:L/AC:H/Au:N/C:N/I:N/A:C) 4.0 CVE-2014-5472 (AV:L/AC:H/Au:N/C:N/I:N/A:C) 4.0 CVE-2014-6410 (AV:L/AC:M/Au:N/C:N/I:N/A:C) 4.7 CVE-2014-9322 (AV:L/AC:L/Au:N/C:C/I:C/A:C) 7.2 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION HP has provided the following information to mitigate the impact of these vulnerabilities. https://softwaresupport.hp.com/group/softwaresupport/search- result/-/facetsearch/document/KM01411792 HISTORY Version:1 (rev.1) - 17 March 2015 Initial release Support: For further information, contact normal HP Services support channel. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information. To get the security-alert PGP key, please send an e-mail message as follows: To: security-alert@hp.com Subject: get key Subscribe: To initiate a subscription to receive future HP Security Bulletins via Email: http://h30046.www3.hp.com/driverAlertProfile.php? regioncode=NA&langcode=USENG&jumpid=in_SC-GEN__driverITRC&topiccode=ITRC On the web page: ITRC security bulletins and patch sign-up Under Step1: your ITRC security bulletins and patches - check ALL categories for which alerts are required and continue. Under Step2: your ITRC operating systems - verify your operating system selections are checked and save. To update an existing subscription: http://h30046.www3.hp.com/subSignIn.php Log in on the web page: Subscriber's choice for Business: sign-in. On the web page: Subscriber's Choice: your profile summary - use Edit Profile to update appropriate sections. To review previously published Security Bulletins visit: http://www.itrc.hp.com/service/cki/secBullArchive.do * The Software Product Category that this Security Bulletin relates to is represented by the 5th and 6th characters of the Bulletin number in the title: GN = HP General SW MA = HP Management Agents MI = Misc. 3rd Party SW MP = HP MPE/iX NS = HP NonStop Servers OV = HP OpenVMS PI = HP Printing & Imaging ST = HP Storage SW TL = HP Trusted Linux TU = HP Tru64 UNIX UX = HP-UX VV = HP VirtualVault System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions. "HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement." Copyright 2015 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. The original glibc bug was reported by Peter Klotz. CVE-2014-7817 Tim Waugh of Red Hat discovered that the WRDE_NOCMD option of the wordexp function did not suppress command execution in all cases. This allows a context-dependent attacker to execute shell commands. CVE-2012-6656 CVE-2014-6040 The charset conversion code for certain IBM multi-byte code pages could perform an out-of-bounds array access, causing the process to crash. In some scenarios, this allows a remote attacker to cause a persistent denial of service. For the upcoming stable distribution (jessie) and the unstable distribution (sid), the CVE-2015-0235 issue has been fixed in version 2.18-1 of the glibc package. We recommend that you upgrade your eglibc packages. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: glibc security update Advisory ID: RHSA-2015:0092-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0092.html Issue date: 2015-01-27 CVE Names: CVE-2015-0235 ===================================================================== 1. Summary: Updated glibc packages that fix one security issue are now available for Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this update as having Critical security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the Name Server Caching Daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. A remote attacker able to make an application call either of these functions could use this flaw to execute arbitrary code with the permissions of the user running the application. (CVE-2015-0235) Red Hat would like to thank Qualys for reporting this issue. All glibc users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1183461 - CVE-2015-0235 glibc: __nss_hostname_digits_dots() heap-based buffer overflow 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: glibc-2.12-1.149.el6_6.5.src.rpm i386: glibc-2.12-1.149.el6_6.5.i686.rpm glibc-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-devel-2.12-1.149.el6_6.5.i686.rpm glibc-headers-2.12-1.149.el6_6.5.i686.rpm glibc-utils-2.12-1.149.el6_6.5.i686.rpm nscd-2.12-1.149.el6_6.5.i686.rpm x86_64: glibc-2.12-1.149.el6_6.5.i686.rpm glibc-2.12-1.149.el6_6.5.x86_64.rpm glibc-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-devel-2.12-1.149.el6_6.5.i686.rpm glibc-devel-2.12-1.149.el6_6.5.x86_64.rpm glibc-headers-2.12-1.149.el6_6.5.x86_64.rpm glibc-utils-2.12-1.149.el6_6.5.x86_64.rpm nscd-2.12-1.149.el6_6.5.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): i386: glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-static-2.12-1.149.el6_6.5.i686.rpm x86_64: glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-static-2.12-1.149.el6_6.5.i686.rpm glibc-static-2.12-1.149.el6_6.5.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: glibc-2.12-1.149.el6_6.5.src.rpm x86_64: glibc-2.12-1.149.el6_6.5.i686.rpm glibc-2.12-1.149.el6_6.5.x86_64.rpm glibc-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-devel-2.12-1.149.el6_6.5.i686.rpm glibc-devel-2.12-1.149.el6_6.5.x86_64.rpm glibc-headers-2.12-1.149.el6_6.5.x86_64.rpm glibc-utils-2.12-1.149.el6_6.5.x86_64.rpm nscd-2.12-1.149.el6_6.5.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): x86_64: glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-static-2.12-1.149.el6_6.5.i686.rpm glibc-static-2.12-1.149.el6_6.5.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: glibc-2.12-1.149.el6_6.5.src.rpm i386: glibc-2.12-1.149.el6_6.5.i686.rpm glibc-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-devel-2.12-1.149.el6_6.5.i686.rpm glibc-headers-2.12-1.149.el6_6.5.i686.rpm glibc-utils-2.12-1.149.el6_6.5.i686.rpm nscd-2.12-1.149.el6_6.5.i686.rpm ppc64: glibc-2.12-1.149.el6_6.5.ppc.rpm glibc-2.12-1.149.el6_6.5.ppc64.rpm glibc-common-2.12-1.149.el6_6.5.ppc64.rpm glibc-debuginfo-2.12-1.149.el6_6.5.ppc.rpm glibc-debuginfo-2.12-1.149.el6_6.5.ppc64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.ppc.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.ppc64.rpm glibc-devel-2.12-1.149.el6_6.5.ppc.rpm glibc-devel-2.12-1.149.el6_6.5.ppc64.rpm glibc-headers-2.12-1.149.el6_6.5.ppc64.rpm glibc-utils-2.12-1.149.el6_6.5.ppc64.rpm nscd-2.12-1.149.el6_6.5.ppc64.rpm s390x: glibc-2.12-1.149.el6_6.5.s390.rpm glibc-2.12-1.149.el6_6.5.s390x.rpm glibc-common-2.12-1.149.el6_6.5.s390x.rpm glibc-debuginfo-2.12-1.149.el6_6.5.s390.rpm glibc-debuginfo-2.12-1.149.el6_6.5.s390x.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.s390.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.s390x.rpm glibc-devel-2.12-1.149.el6_6.5.s390.rpm glibc-devel-2.12-1.149.el6_6.5.s390x.rpm glibc-headers-2.12-1.149.el6_6.5.s390x.rpm glibc-utils-2.12-1.149.el6_6.5.s390x.rpm nscd-2.12-1.149.el6_6.5.s390x.rpm x86_64: glibc-2.12-1.149.el6_6.5.i686.rpm glibc-2.12-1.149.el6_6.5.x86_64.rpm glibc-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-devel-2.12-1.149.el6_6.5.i686.rpm glibc-devel-2.12-1.149.el6_6.5.x86_64.rpm glibc-headers-2.12-1.149.el6_6.5.x86_64.rpm glibc-utils-2.12-1.149.el6_6.5.x86_64.rpm nscd-2.12-1.149.el6_6.5.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): i386: glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-static-2.12-1.149.el6_6.5.i686.rpm ppc64: glibc-debuginfo-2.12-1.149.el6_6.5.ppc.rpm glibc-debuginfo-2.12-1.149.el6_6.5.ppc64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.ppc.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.ppc64.rpm glibc-static-2.12-1.149.el6_6.5.ppc.rpm glibc-static-2.12-1.149.el6_6.5.ppc64.rpm s390x: glibc-debuginfo-2.12-1.149.el6_6.5.s390.rpm glibc-debuginfo-2.12-1.149.el6_6.5.s390x.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.s390.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.s390x.rpm glibc-static-2.12-1.149.el6_6.5.s390.rpm glibc-static-2.12-1.149.el6_6.5.s390x.rpm x86_64: glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-static-2.12-1.149.el6_6.5.i686.rpm glibc-static-2.12-1.149.el6_6.5.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: glibc-2.12-1.149.el6_6.5.src.rpm i386: glibc-2.12-1.149.el6_6.5.i686.rpm glibc-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-devel-2.12-1.149.el6_6.5.i686.rpm glibc-headers-2.12-1.149.el6_6.5.i686.rpm glibc-utils-2.12-1.149.el6_6.5.i686.rpm nscd-2.12-1.149.el6_6.5.i686.rpm x86_64: glibc-2.12-1.149.el6_6.5.i686.rpm glibc-2.12-1.149.el6_6.5.x86_64.rpm glibc-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-devel-2.12-1.149.el6_6.5.i686.rpm glibc-devel-2.12-1.149.el6_6.5.x86_64.rpm glibc-headers-2.12-1.149.el6_6.5.x86_64.rpm glibc-utils-2.12-1.149.el6_6.5.x86_64.rpm nscd-2.12-1.149.el6_6.5.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): i386: glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-static-2.12-1.149.el6_6.5.i686.rpm x86_64: glibc-debuginfo-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.5.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.5.x86_64.rpm glibc-static-2.12-1.149.el6_6.5.i686.rpm glibc-static-2.12-1.149.el6_6.5.x86_64.rpm Red Hat Enterprise Linux Client (v. 7): Source: glibc-2.17-55.el7_0.5.src.rpm x86_64: glibc-2.17-55.el7_0.5.i686.rpm glibc-2.17-55.el7_0.5.x86_64.rpm glibc-common-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-common-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-common-2.17-55.el7_0.5.x86_64.rpm glibc-devel-2.17-55.el7_0.5.i686.rpm glibc-devel-2.17-55.el7_0.5.x86_64.rpm glibc-headers-2.17-55.el7_0.5.x86_64.rpm glibc-utils-2.17-55.el7_0.5.x86_64.rpm nscd-2.17-55.el7_0.5.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: glibc-debuginfo-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-common-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-common-2.17-55.el7_0.5.x86_64.rpm glibc-static-2.17-55.el7_0.5.i686.rpm glibc-static-2.17-55.el7_0.5.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: glibc-2.17-55.el7_0.5.src.rpm x86_64: glibc-2.17-55.el7_0.5.i686.rpm glibc-2.17-55.el7_0.5.x86_64.rpm glibc-common-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-common-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-common-2.17-55.el7_0.5.x86_64.rpm glibc-devel-2.17-55.el7_0.5.i686.rpm glibc-devel-2.17-55.el7_0.5.x86_64.rpm glibc-headers-2.17-55.el7_0.5.x86_64.rpm glibc-utils-2.17-55.el7_0.5.x86_64.rpm nscd-2.17-55.el7_0.5.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: glibc-debuginfo-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-common-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-common-2.17-55.el7_0.5.x86_64.rpm glibc-static-2.17-55.el7_0.5.i686.rpm glibc-static-2.17-55.el7_0.5.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: glibc-2.17-55.el7_0.5.src.rpm ppc64: glibc-2.17-55.el7_0.5.ppc.rpm glibc-2.17-55.el7_0.5.ppc64.rpm glibc-common-2.17-55.el7_0.5.ppc64.rpm glibc-debuginfo-2.17-55.el7_0.5.ppc.rpm glibc-debuginfo-2.17-55.el7_0.5.ppc64.rpm glibc-debuginfo-common-2.17-55.el7_0.5.ppc.rpm glibc-debuginfo-common-2.17-55.el7_0.5.ppc64.rpm glibc-devel-2.17-55.el7_0.5.ppc.rpm glibc-devel-2.17-55.el7_0.5.ppc64.rpm glibc-headers-2.17-55.el7_0.5.ppc64.rpm glibc-utils-2.17-55.el7_0.5.ppc64.rpm nscd-2.17-55.el7_0.5.ppc64.rpm s390x: glibc-2.17-55.el7_0.5.s390.rpm glibc-2.17-55.el7_0.5.s390x.rpm glibc-common-2.17-55.el7_0.5.s390x.rpm glibc-debuginfo-2.17-55.el7_0.5.s390.rpm glibc-debuginfo-2.17-55.el7_0.5.s390x.rpm glibc-debuginfo-common-2.17-55.el7_0.5.s390.rpm glibc-debuginfo-common-2.17-55.el7_0.5.s390x.rpm glibc-devel-2.17-55.el7_0.5.s390.rpm glibc-devel-2.17-55.el7_0.5.s390x.rpm glibc-headers-2.17-55.el7_0.5.s390x.rpm glibc-utils-2.17-55.el7_0.5.s390x.rpm nscd-2.17-55.el7_0.5.s390x.rpm x86_64: glibc-2.17-55.el7_0.5.i686.rpm glibc-2.17-55.el7_0.5.x86_64.rpm glibc-common-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-common-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-common-2.17-55.el7_0.5.x86_64.rpm glibc-devel-2.17-55.el7_0.5.i686.rpm glibc-devel-2.17-55.el7_0.5.x86_64.rpm glibc-headers-2.17-55.el7_0.5.x86_64.rpm glibc-utils-2.17-55.el7_0.5.x86_64.rpm nscd-2.17-55.el7_0.5.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: glibc-debuginfo-2.17-55.el7_0.5.ppc.rpm glibc-debuginfo-2.17-55.el7_0.5.ppc64.rpm glibc-debuginfo-common-2.17-55.el7_0.5.ppc.rpm glibc-debuginfo-common-2.17-55.el7_0.5.ppc64.rpm glibc-static-2.17-55.el7_0.5.ppc.rpm glibc-static-2.17-55.el7_0.5.ppc64.rpm s390x: glibc-debuginfo-2.17-55.el7_0.5.s390.rpm glibc-debuginfo-2.17-55.el7_0.5.s390x.rpm glibc-debuginfo-common-2.17-55.el7_0.5.s390.rpm glibc-debuginfo-common-2.17-55.el7_0.5.s390x.rpm glibc-static-2.17-55.el7_0.5.s390.rpm glibc-static-2.17-55.el7_0.5.s390x.rpm x86_64: glibc-debuginfo-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-common-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-common-2.17-55.el7_0.5.x86_64.rpm glibc-static-2.17-55.el7_0.5.i686.rpm glibc-static-2.17-55.el7_0.5.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: glibc-2.17-55.el7_0.5.src.rpm x86_64: glibc-2.17-55.el7_0.5.i686.rpm glibc-2.17-55.el7_0.5.x86_64.rpm glibc-common-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-common-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-common-2.17-55.el7_0.5.x86_64.rpm glibc-devel-2.17-55.el7_0.5.i686.rpm glibc-devel-2.17-55.el7_0.5.x86_64.rpm glibc-headers-2.17-55.el7_0.5.x86_64.rpm glibc-utils-2.17-55.el7_0.5.x86_64.rpm nscd-2.17-55.el7_0.5.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: glibc-debuginfo-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-2.17-55.el7_0.5.x86_64.rpm glibc-debuginfo-common-2.17-55.el7_0.5.i686.rpm glibc-debuginfo-common-2.17-55.el7_0.5.x86_64.rpm glibc-static-2.17-55.el7_0.5.i686.rpm glibc-static-2.17-55.el7_0.5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0235 https://access.redhat.com/security/updates/classification/#critical 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFUx9bmXlSAg2UNWIIRAjP4AJ9/EPFLyhSuapG8Lie71zPk6VaF8wCfVAw2 VIBda0hF+i0zAuST73ezXzI= =w5UI -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . Background ========== The GNU C library is the standard C library used by Gentoo Linux systems. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-libs/glibc < 2.19-r1 >= 2.19-r1 Description =========== Multiple vulnerabilities have been discovered in the GNU C Library. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All glibc users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sys-libs/glibc-2.19-r1" References ========== [ 1 ] CVE-2012-3404 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3404 [ 2 ] CVE-2012-3405 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3405 [ 3 ] CVE-2012-3406 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3406 [ 4 ] CVE-2012-3480 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3480 [ 5 ] CVE-2012-4412 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4412 [ 6 ] CVE-2012-4424 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4424 [ 7 ] CVE-2012-6656 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-6656 [ 8 ] CVE-2013-0242 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0242 [ 9 ] CVE-2013-1914 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1914 [ 10 ] CVE-2013-2207 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2207 [ 11 ] CVE-2013-4237 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4237 [ 12 ] CVE-2013-4332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4332 [ 13 ] CVE-2013-4458 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4458 [ 14 ] CVE-2013-4788 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4788 [ 15 ] CVE-2014-4043 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-4043 [ 16 ] CVE-2015-0235 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0235 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201503-04.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. SEC Consult Vulnerability Lab Security Advisory < 20210901-0 > ======================================================================= title: Multiple vulnerabilities product: see "Vulnerable / tested versions" vulnerable version: see "Vulnerable / tested versions" fixed version: see "Solution" CVE number: CVE-2021-39278, CVE-2021-39279 impact: High homepage: https://www.moxa.com/ found: 2020-08-31 by: T. Weber (Office Vienna) SEC Consult Vulnerability Lab An integrated part of SEC Consult, an Atos company Europe | Asia | North America https://www.sec-consult.com ======================================================================= Vendor description: ------------------- "Together, We Create Change Moxa is committed to making a positive impact around the world. We put our all behind this commitment--from our employees, to our products and supply chain. In our local communities, we nurture and support the spirit of volunteering. We encourage our employees to contribute to community development, with an emphasis on ecology, education, and health. In our products, we invest in social awareness programs and environment-friendly policies at every stage of the product lifecycle. We make sure our manufacturing meets the highest standards with regards to quality, ethics, and sustainability." Source: https://www.moxa.com/en/about-us/corporate-responsibility Business recommendation: ------------------------ SEC Consult recommends to immediately apply the available patches from the vendor. A thorough security review should be performed by security professionals to identify further potential security issues. Vulnerability overview/description: ----------------------------------- 1) Authenticated Command Injection (CVE-2021-39279) An authenticated command injection vulnerability can be triggered by issuing a GET request to the "/forms/web_importTFTP" CGI program which is available on the web interface. An attacker can abuse this vulnerability to compromise the operating system of the device. This issue was found by emulating the firmware of the device. 2) Reflected Cross-Site Scripting via Manipulated Config-File (CVE-2021-39278) Via a crafted config-file, a reflected cross-site scripting vulnerability can be exploited in the context of the victim's browser. This config-file can be uploaded to the device via the "Config Import Export" tab in the main menu. 3) Known GNU glibc Vulnerabilities (CVE-2015-0235) The used GNU glibc in version 2.9 is outdated and contains multiple known vulnerabilities. One of the discovered vulnerabilities (CVE-2015-0235, gethostbyname "GHOST" buffer overflow) was verified by using the MEDUSA scalable firmware runtime. 4) Multiple Outdated Software Components Multiple outdated software components containing vulnerabilities were found by the IoT Inspector. The vulnerabilities 1), 2) and 3) were manually verified on an emulated device by using the MEDUSA scalable firmware runtime. Proof of concept: ----------------- 1) Authenticated Command Injection (CVE-2021-39279) The vulnerability can be triggered by navigating in the web interface to the tab: "Main Menu"->"Maintenance"->"Config Import Export" The "TFTP Import" menu is prone to command injection via all parameters. To exploit the vulnerability, an IP address, a configuration path and a filename must be set. If the filename is used to trigger the exploit, the payload in the interceptor proxy would be: http://192.168.1.1/forms/web_importTFTP?servIP=192.168.1.1&configPath=/&fileName=name|`ping localhost -c 100` 2) Reflected Cross-Site Scripting via Manipulated Config-File (CVE-2021-39278) The vulnerability can be triggered by navigating in the web interface to the tab: "Main Menu"->"Maintenance"->"Config Import Export" The "Config Import" menu is prone to reflected cross-site scripting via the upload of config files. Example of malicious config file: ------------------------------------------------------------------------------- [board] deviceName="WAC-2004_0000</span><script>alert(document.cookie)</script>" deviceLocation="" [..] ------------------------------------------------------------------------------- Uploading such a crafted file triggers cross-site scripting as the erroneous value is displayed without filtering characters. 3) Known GNU glibc Vulnerabilities (CVE-2015-0235) GNU glibc version 2.9 contains multiple CVEs like: CVE-2016-1234, CVE-2015-7547, CVE-2013-7423, CVE-2013-1914, and more. The gethostbyname buffer overflow vulnerability (GHOST) was checked with the help of the exploit code from https://seclists.org/oss-sec/2015/q1/274. It was compiled and executed on the emulated device to test the system. 4) Multiple Outdated Software Components The IoT Inspector recognized multiple outdated software components with known vulnerabilities: BusyBox 1.18.5 06/2011 Dropbear SSH 2011.54 11/2011 GNU glibc 2.9 02/2009 Linux Kernel 2.6.27 10/2008 OpenSSL 0.9.7g 04/2005 Only found in the program "iw_director" OpenSSL 1.0.0 03/2010 Vulnerable / tested versions: ----------------------------- The following firmware versions for various devices have been identified to be vulnerable: * WAC-2004 / 1.7 * WAC-1001 / 2.1 * WAC-1001-T / 2.1 * OnCell G3470A-LTE-EU / 1.7 * OnCell G3470A-LTE-EU-T / 1.7 * TAP-323-EU-CT-T / 1.3 * TAP-323-US-CT-T / 1.3 * TAP-323-JP-CT-T / 1.3 * WDR-3124A-EU / 2.3 * WDR-3124A-EU-T / 2.3 * WDR-3124A-US / 2.3 * WDR-3124A-US-T / 2.3 Vendor contact timeline: ------------------------ 2020-10-09: Contacting vendor through moxa.csrt@moxa.com. 2020-10-12: Contact sends PGP key for encrypted communication and asks for the detailed advisory. Sent encrypted advisory to vendor. 2020-11-06: Status update from vendor regarding technical analysis. Vendor requested more time for fixing the vulnerabilities as more products are affected. 2020-11-09: Granted more time for fixing to vendor. 2020-11-10: Vendor asked for next steps regarding the advisory publication. 2020-11-11: Asked vendor for an estimation when a public disclosure is possible. 2020-11-16: Vendor responded that the product team can give a rough feedback. 2020-11-25: Asked for a status update. 2020-11-25: Vendor responded that the investigation is not done yet. 2020-12-14: Vendor provided a list of potential affected devices and stated that full investigation may take until January 2021 due to the list of CVEs that were provided with the appended IoT Inspector report. The patches may be available until June 2021. 2020-12-15: Shifted next status update round with vendor on May 2021. 2020-12-23: Vendor provided full list of affected devices. 2021-02-05: Vendor sieved out the found issues from 4) manually and provided a full list of confirmed vulnerabilities. WAC-2004 phased-out in 2019. 2021-02-21: Confirmed receive of vulnerabilities, next status update in May 2021. 2021-06-10: Asking for an update. 2021-06-15: Vendor stated, that the update will be provided in the next days. 2021-06-21: Vendor will give an update in the next week as Covid gets worse in Taiwan. 2021-06-23: Vendor stated, that patches are under development. Vendor needs more time to finish the patches. 2021-06-24: Set release date to 2021-09-01. 2021-07-02: Vendor provides status updates. 2021-08-16: Vendor provides status updates. 2021-08-17: Vendor asks for CVE IDs and stated, that WDR-3124A has phased-out. 2021-08-20: Sent assigned CVE-IDs to vendor. Asked for fixed version numbers. 2021-08-31: Vendor provides fixed firmware version numbers and the advisory links. 2021-09-01: Coordinated release of security advisory. Solution: --------- According to the vendor the following patches must be applied to fix issues: * WAC-1001 / 2.1.5 * WAC-1001-T / 2.1.5 * OnCell G3470A-LTE-EU / 1.7.4 * OnCell G3470A-LTE-EU-T / 1.7.4 * TAP-323-EU-CT-T / 1.8.1 * TAP-323-US-CT-T / 1.8.1 * TAP-323-JP-CT-T / 1.8.1 The Moxa Technical Support must be contacted for requesting the security patches. The corresponding security advisories for the affected devices are available on the vendor's website: TAP-323/WAC-1001/WAC-2004 https://www.moxa.com/en/support/product-support/security-advisory/tap-323-wac-1001-2004-wireless-ap-bridge-client-vulnerabilities OnCell G3470A-LTE/WDR-3124A https://www.moxa.com/en/support/product-support/security-advisory/oncell-g3470a-wdr-3124a-cellular-gateways-router-vulnerabilities The following device models are EOL and should be replaced: * WAC-2004 * WDR-3124A-EU * WDR-3124A-EU-T * WDR-3124A-US * WDR-3124A-US-T Workaround: ----------- None. Advisory URL: ------------- https://sec-consult.com/vulnerability-lab/ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SEC Consult Vulnerability Lab SEC Consult, an Atos company Europe | Asia | North America About SEC Consult Vulnerability Lab The SEC Consult Vulnerability Lab is an integrated part of SEC Consult, an Atos company. It ensures the continued knowledge gain of SEC Consult in the field of network and application security to stay ahead of the attacker. The SEC Consult Vulnerability Lab supports high-quality penetration testing and the evaluation of new offensive and defensive technologies for our customers. Hence our customers obtain the most current information about vulnerabilities and valid recommendation about the risk profile of new technologies. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Interested to work with the experts of SEC Consult? Send us your application https://sec-consult.com/career/ Interested in improving your cyber security with the experts of SEC Consult? Contact our local offices https://sec-consult.com/contact/ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Mail: research at sec-consult dot com Web: https://www.sec-consult.com Blog: http://blog.sec-consult.com Twitter: https://twitter.com/sec_consult EOF Thomas Weber / @2021

Trust: 2.43

sources: NVD: CVE-2015-0235 // CERT/CC: VU#967332 // VULHUB: VHN-78181 // VULMON: CVE-2015-0235 // PACKETSTORM: 130768 // PACKETSTORM: 134196 // PACKETSTORM: 131015 // PACKETSTORM: 130098 // PACKETSTORM: 130114 // PACKETSTORM: 130702 // PACKETSTORM: 164014

AFFECTED PRODUCTS

vendor:ibmmodel:pureapplication systemscope:eqversion:1.1.0.0

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:7.0

Trust: 1.0

vendor:phpmodel:phpscope:gteversion:5.5.0

Trust: 1.0

vendor:oraclemodel:communications webrtc session controllerscope:eqversion:7.1

Trust: 1.0

vendor:phpmodel:phpscope:ltversion:5.4.38

Trust: 1.0

vendor:redhatmodel:virtualizationscope:eqversion:6.0

Trust: 1.0

vendor:applemodel:mac os xscope:ltversion:10.11.1

Trust: 1.0

vendor:oraclemodel:communications policy managementscope:eqversion:9.9.1

Trust: 1.0

vendor:oraclemodel:vm virtualboxscope:ltversion:5.1.24

Trust: 1.0

vendor:oraclemodel:communications policy managementscope:eqversion:12.1.1

Trust: 1.0

vendor:oraclemodel:communications webrtc session controllerscope:eqversion:7.2

Trust: 1.0

vendor:gnumodel:glibcscope:ltversion:2.18

Trust: 1.0

vendor:oraclemodel:communications user data repositoryscope:lteversion:10.0.1

Trust: 1.0

vendor:oraclemodel:exalogic infrastructurescope:eqversion:1.0

Trust: 1.0

vendor:oraclemodel:communications webrtc session controllerscope:eqversion:7.0

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:8.0

Trust: 1.0

vendor:oraclemodel:communications eagle application processorscope:eqversion:16.0

Trust: 1.0

vendor:oraclemodel:communications session border controllerscope:eqversion:7.2.0

Trust: 1.0

vendor:phpmodel:phpscope:ltversion:5.6.6

Trust: 1.0

vendor:oraclemodel:communications eagle lnp application processorscope:eqversion:10.0

Trust: 1.0

vendor:oraclemodel:communications session border controllerscope:ltversion:7.2.0

Trust: 1.0

vendor:phpmodel:phpscope:ltversion:5.5.22

Trust: 1.0

vendor:oraclemodel:communications policy managementscope:eqversion:11.5

Trust: 1.0

vendor:oraclemodel:linuxscope:eqversion:5

Trust: 1.0

vendor:ibmmodel:pureapplication systemscope:eqversion:1.0.0.0

Trust: 1.0

vendor:gnumodel:glibcscope:gteversion:2.0

Trust: 1.0

vendor:phpmodel:phpscope:gteversion:5.4.0

Trust: 1.0

vendor:oraclemodel:communications policy managementscope:eqversion:10.4.1

Trust: 1.0

vendor:oraclemodel:communications policy managementscope:eqversion:9.7.3

Trust: 1.0

vendor:oraclemodel:communications application session controllerscope:ltversion:3.7.1

Trust: 1.0

vendor:oraclemodel:linuxscope:eqversion:7

Trust: 1.0

vendor:ibmmodel:pureapplication systemscope:eqversion:2.0.0.0

Trust: 1.0

vendor:oraclemodel:communications lsmsscope:eqversion:13.1

Trust: 1.0

vendor:phpmodel:phpscope:gteversion:5.6.0

Trust: 1.0

vendor:oraclemodel:exalogic infrastructurescope:eqversion:2.0

Trust: 1.0

vendor:oraclemodel:communications user data repositoryscope:gteversion:10.0.0

Trust: 1.0

vendor:ibmmodel:security access manager for enterprise single sign-onscope:eqversion:8.2

Trust: 1.0

vendor:oraclemodel:communications session border controllerscope:eqversion:8.0.0

Trust: 1.0

vendor:arch linuxmodel: - scope: - version: -

Trust: 0.8

vendor:blue coatmodel: - scope: - version: -

Trust: 0.8

vendor:ciscomodel: - scope: - version: -

Trust: 0.8

vendor:citrixmodel: - scope: - version: -

Trust: 0.8

vendor:debian gnu linuxmodel: - scope: - version: -

Trust: 0.8

vendor:f5model: - scope: - version: -

Trust: 0.8

vendor:gentoo linuxmodel: - scope: - version: -

Trust: 0.8

vendor:junipermodel: - scope: - version: -

Trust: 0.8

vendor:necmodel: - scope: - version: -

Trust: 0.8

vendor:netappmodel: - scope: - version: -

Trust: 0.8

vendor:openwall gnu linuxmodel: - scope: - version: -

Trust: 0.8

vendor:red hatmodel: - scope: - version: -

Trust: 0.8

vendor:suse linuxmodel: - scope: - version: -

Trust: 0.8

vendor:slackware linuxmodel: - scope: - version: -

Trust: 0.8

vendor:ubuntumodel: - scope: - version: -

Trust: 0.8

vendor:opensusemodel: - scope: - version: -

Trust: 0.8

sources: CERT/CC: VU#967332 // NVD: CVE-2015-0235

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0235
value: HIGH

Trust: 1.0

NVD: CVE-2015-0235
value: HIGH

Trust: 0.8

VULHUB: VHN-78181
value: HIGH

Trust: 0.1

VULMON: CVE-2015-0235
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-0235
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: CVE-2015-0235
severity: HIGH
baseScore: 10.0
vectorString: NONE
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-78181
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#967332 // VULHUB: VHN-78181 // VULMON: CVE-2015-0235 // NVD: CVE-2015-0235

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.1

problemtype:CWE-119

Trust: 0.1

sources: VULHUB: VHN-78181 // NVD: CVE-2015-0235

THREAT TYPE

remote

Trust: 0.2

sources: PACKETSTORM: 130768 // PACKETSTORM: 130114

TYPE

arbitrary

Trust: 0.2

sources: PACKETSTORM: 134196 // PACKETSTORM: 130702

EXPLOIT AVAILABILITY

sources: CERT/CC: VU#967332 // VULHUB: VHN-78181 // VULMON: CVE-2015-0235

PATCH

title:Red Hat: Critical: glibc security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20150092 - Security Advisory

Trust: 0.1

title:Red Hat: Critical: glibc security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20150099 - Security Advisory

Trust: 0.1

title:Red Hat: Critical: glibc security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20150090 - Security Advisory

Trust: 0.1

title:Red Hat: Critical: glibc security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20150101 - Security Advisory

Trust: 0.1

title:Ubuntu Security Notice: eglibc vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-2485-1

Trust: 0.1

title:Debian CVElist Bug Report Logs: [CVE-2015-0235]: heap-based buffer overflow in __nss_hostname_digits_dots()url:https://vulmon.com/vendoradvisory?qidtp=debian_cvelist_bugreportlogs&qid=113c5c83951cdd4f600ba9535d75b039

Trust: 0.1

title:Red Hat: Critical: rhev-hypervisor6 security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20150126 - Security Advisory

Trust: 0.1

title:Amazon Linux AMI: ALAS-2015-473url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2015-473

Trust: 0.1

title:Debian CVElist Bug Report Logs: php5: CVE-2015-2305: Henry Spencer regular expressions (regex) library contains a heap overflow vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=debian_cvelist_bugreportlogs&qid=bdd6a1a9c3a69d15bd8b1f4350ea9ee9

Trust: 0.1

title:Red Hat: CVE-2015-0235url:https://vulmon.com/vendoradvisory?qidtp=red_hat_cve_database&qid=CVE-2015-0235

Trust: 0.1

title:Citrix Security Bulletins: CVE-2015-0235 - Citrix Security Advisory for glibc GHOST Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=citrix_security_bulletins&qid=ffce7496a0291c4ef7404e773fb59f7a

Trust: 0.1

title:Amazon Linux AMI: ALAS-2015-493url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2015-493

Trust: 0.1

title:Amazon Linux AMI: ALAS-2015-494url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2015-494

Trust: 0.1

title:Debian Security Advisories: DSA-3142-1 eglibc -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=371dc04fd45b8ac3bf9022a7b8a1b738

Trust: 0.1

title:CVE-2015-0235url:https://github.com/r0otshell/CVE-2015-0235

Trust: 0.1

title:CVE-2015-0235-test Note!url:https://github.com/aaronfay/CVE-2015-0235-test

Trust: 0.1

title:CVE_2015_0235 Integration into masterfiles Activate it in your policy (with autorun)url:https://github.com/nickanderson/cfengine-CVE_2015_0235

Trust: 0.1

title:CVE-2015-0235-workaroundurl:https://github.com/makelinux/CVE-2015-0235-workaround

Trust: 0.1

title:CVE-2015-0235-cookbookurl:https://github.com/mikesplain/CVE-2015-0235-cookbook

Trust: 0.1

title:ghosturl:https://github.com/piyokango/ghost

Trust: 0.1

title:Ghostcheckurl:https://github.com/chayim/GHOSTCHECK-cve-2015-0235

Trust: 0.1

title:CVE-2015-0235url:https://github.com/tobyzxj/CVE-2015-0235

Trust: 0.1

title:ghost-checker Usage Creditsurl:https://github.com/fser/ghost-checker

Trust: 0.1

title:cookbook-update-glibcurl:https://github.com/koudaiii/cookbook-update-glibc

Trust: 0.1

title:Peekr-APIurl:https://github.com/JJediny/peekr-api

Trust: 0.1

title:cookbook-update-glibcurl:https://github.com/koudaiii-archives/cookbook-update-glibc

Trust: 0.1

title:ghostbusters15url:https://github.com/F88/ghostbusters15

Trust: 0.1

title:ANSIBLE EXAMPLE CVE-2015-0235-test Note!url:https://github.com/pebreo/ansible-simple-example

Trust: 0.1

title:CVE collectedurl:https://github.com/geekben/cve-collections

Trust: 0.1

title:CVE advisories testsurl:https://github.com/arthepsy/cve-tests

Trust: 0.1

title:LibCare -- Patch Userspace Code on Live Processesurl:https://github.com/Rtoax/libcare

Trust: 0.1

title:CVE-glibcurl:https://github.com/alanmeyer/CVE-glibc

Trust: 0.1

title:LibCare -- Patch Userspace Code on Live Processesurl:https://github.com/cloudlinux/libcare

Trust: 0.1

title:https://github.com/r3p3r/1N3-Exploitsurl:https://github.com/r3p3r/1N3-Exploits

Trust: 0.1

title:https://github.com/dineshkumarc987/Exploitsurl:https://github.com/dineshkumarc987/Exploits

Trust: 0.1

title:https://github.com/1N3/Exploitsurl:https://github.com/1N3/Exploits

Trust: 0.1

title:https://github.com/1N3/1N3url:https://github.com/1N3/1N3

Trust: 0.1

title:https://github.com/xyongcn/exploiturl:https://github.com/xyongcn/exploit

Trust: 0.1

title:CoreOS Clair Laburl:https://github.com/sjourdan/clair-lab

Trust: 0.1

title:rhsecapiurl:https://github.com/ryran/rhsecapi

Trust: 0.1

title:rhsecapiurl:https://github.com/RedHatOfficial/rhsecapi

Trust: 0.1

title:rhsecapiurl:https://github.com/RedHatProductSecurity/cve-pylib

Trust: 0.1

title:LinuxFlawurl:https://github.com/mudongliang/LinuxFlaw

Trust: 0.1

title:LinuxFlawurl:https://github.com/oneoy/cve-

Trust: 0.1

title:Awesome CVE PoCurl:https://github.com/xbl3/awesome-cve-poc_qazbnm456

Trust: 0.1

title:Awesome CVE PoCurl:https://github.com/lnick2023/nicenice

Trust: 0.1

title:Awesome CVE PoCurl:https://github.com/qazbnm456/awesome-cve-poc

Trust: 0.1

title:The Registerurl:https://www.theregister.co.uk/2015/01/28/ghost_linux_megavuln_analysis/

Trust: 0.1

title:The Registerurl:https://www.theregister.co.uk/2015/01/27/glibc_ghost_vulnerability/

Trust: 0.1

sources: VULMON: CVE-2015-0235

EXTERNAL IDS

db:NVDid:CVE-2015-0235

Trust: 2.7

db:PACKETSTORMid:164014

Trust: 1.3

db:PACKETSTORMid:130768

Trust: 1.3

db:BIDid:91787

Trust: 1.2

db:BIDid:72325

Trust: 1.2

db:PACKETSTORMid:167552

Trust: 1.2

db:PACKETSTORMid:130974

Trust: 1.2

db:PACKETSTORMid:153278

Trust: 1.2

db:PACKETSTORMid:130171

Trust: 1.2

db:SECUNIAid:62883

Trust: 1.2

db:SECUNIAid:62690

Trust: 1.2

db:SECUNIAid:62871

Trust: 1.2

db:SECUNIAid:62680

Trust: 1.2

db:SECUNIAid:62517

Trust: 1.2

db:SECUNIAid:62640

Trust: 1.2

db:SECUNIAid:62715

Trust: 1.2

db:SECUNIAid:62812

Trust: 1.2

db:SECUNIAid:62667

Trust: 1.2

db:SECUNIAid:62879

Trust: 1.2

db:SECUNIAid:62813

Trust: 1.2

db:SECUNIAid:62698

Trust: 1.2

db:SECUNIAid:62681

Trust: 1.2

db:SECUNIAid:62692

Trust: 1.2

db:SECUNIAid:62758

Trust: 1.2

db:SECUNIAid:62870

Trust: 1.2

db:SECUNIAid:62816

Trust: 1.2

db:SECUNIAid:62691

Trust: 1.2

db:SECUNIAid:62688

Trust: 1.2

db:SECUNIAid:62865

Trust: 1.2

db:JUNIPERid:JSA10671

Trust: 1.2

db:SECTRACKid:1032909

Trust: 1.2

db:MCAFEEid:SB10100

Trust: 1.2

db:SIEMENSid:SSA-994726

Trust: 1.2

db:OPENWALLid:OSS-SECURITY/2021/05/04/7

Trust: 1.2

db:OPENWALLid:OSS-SECURITY/2015/01/27/9

Trust: 0.8

db:CERT/CCid:VU#967332

Trust: 0.8

db:PACKETSTORMid:134196

Trust: 0.2

db:PACKETSTORMid:130114

Trust: 0.2

db:EXPLOIT-DBid:35951

Trust: 0.2

db:PACKETSTORMid:131867

Trust: 0.1

db:PACKETSTORMid:130115

Trust: 0.1

db:PACKETSTORMid:131214

Trust: 0.1

db:PACKETSTORMid:130216

Trust: 0.1

db:PACKETSTORMid:130100

Trust: 0.1

db:PACKETSTORMid:130134

Trust: 0.1

db:PACKETSTORMid:130135

Trust: 0.1

db:PACKETSTORMid:130099

Trust: 0.1

db:PACKETSTORMid:130163

Trust: 0.1

db:PACKETSTORMid:130333

Trust: 0.1

db:EXPLOIT-DBid:36421

Trust: 0.1

db:CNNVDid:CNNVD-201501-658

Trust: 0.1

db:SEEBUGid:SSVID-89237

Trust: 0.1

db:VULHUBid:VHN-78181

Trust: 0.1

db:VULMONid:CVE-2015-0235

Trust: 0.1

db:PACKETSTORMid:131015

Trust: 0.1

db:PACKETSTORMid:130098

Trust: 0.1

db:PACKETSTORMid:130702

Trust: 0.1

sources: CERT/CC: VU#967332 // VULHUB: VHN-78181 // VULMON: CVE-2015-0235 // PACKETSTORM: 130768 // PACKETSTORM: 134196 // PACKETSTORM: 131015 // PACKETSTORM: 130098 // PACKETSTORM: 130114 // PACKETSTORM: 130702 // PACKETSTORM: 164014 // NVD: CVE-2015-0235

REFERENCES

url:https://www.qualys.com/research/security-advisories/ghost-cve-2015-0235.txt

Trust: 2.1

url:http://lists.apple.com/archives/security-announce/2015/jun/msg00002.html

Trust: 1.2

url:http://lists.apple.com/archives/security-announce/2015/sep/msg00008.html

Trust: 1.2

url:http://lists.apple.com/archives/security-announce/2015/oct/msg00005.html

Trust: 1.2

url:http://www.securityfocus.com/bid/72325

Trust: 1.2

url:http://www.securityfocus.com/bid/91787

Trust: 1.2

url:http://seclists.org/oss-sec/2015/q1/269

Trust: 1.2

url:http://seclists.org/oss-sec/2015/q1/274

Trust: 1.2

url:http://www.securityfocus.com/archive/1/534845/100/0/threaded

Trust: 1.2

url:https://seclists.org/bugtraq/2019/jun/14

Trust: 1.2

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20150128-ghost

Trust: 1.2

url:http://blogs.sophos.com/2015/01/29/sophos-products-and-the-ghost-vulnerability-affecting-linux/

Trust: 1.2

url:http://linux.oracle.com/errata/elsa-2015-0090.html

Trust: 1.2

url:http://linux.oracle.com/errata/elsa-2015-0092.html

Trust: 1.2

url:http://support.apple.com/kb/ht204942

Trust: 1.2

url:http://www-01.ibm.com/support/docview.wss?uid=swg21695695

Trust: 1.2

url:http://www-01.ibm.com/support/docview.wss?uid=swg21695774

Trust: 1.2

url:http://www-01.ibm.com/support/docview.wss?uid=swg21695835

Trust: 1.2

url:http://www-01.ibm.com/support/docview.wss?uid=swg21695860

Trust: 1.2

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696131

Trust: 1.2

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696243

Trust: 1.2

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696526

Trust: 1.2

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696600

Trust: 1.2

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696602

Trust: 1.2

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696618

Trust: 1.2

url:http://www.idirect.net/partners/~/media/files/cve/idirect-posted-common-vulnerabilities-and-exposures.pdf

Trust: 1.2

url:http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

Trust: 1.2

url:http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html

Trust: 1.2

url:http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html

Trust: 1.2

url:http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html

Trust: 1.2

url:http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html

Trust: 1.2

url:http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html

Trust: 1.2

url:http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html

Trust: 1.2

url:http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html

Trust: 1.2

url:http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html

Trust: 1.2

url:http://www.websense.com/support/article/kbarticle/vulnerabilities-resolved-in-triton-apx-version-8-0

Trust: 1.2

url:https://bto.bluecoat.com/security-advisory/sa90

Trust: 1.2

url:https://cert-portal.siemens.com/productcert/pdf/ssa-994726.pdf

Trust: 1.2

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04874668

Trust: 1.2

url:https://help.ecostruxureit.com/display/public/uadco8x/struxureware+data+center+operation+software+vulnerability+fixes

Trust: 1.2

url:https://security.netapp.com/advisory/ntap-20150127-0001/

Trust: 1.2

url:https://support.apple.com/ht205267

Trust: 1.2

url:https://support.apple.com/ht205375

Trust: 1.2

url:https://www.f-secure.com/en/web/labs_global/fsc-2015-1

Trust: 1.2

url:https://www.sophos.com/en-us/support/knowledgebase/121879.aspx

Trust: 1.2

url:http://www.debian.org/security/2015/dsa-3142

Trust: 1.2

url:http://seclists.org/fulldisclosure/2015/jan/111

Trust: 1.2

url:http://seclists.org/fulldisclosure/2019/jun/18

Trust: 1.2

url:http://seclists.org/fulldisclosure/2021/sep/0

Trust: 1.2

url:http://seclists.org/fulldisclosure/2022/jun/36

Trust: 1.2

url:https://security.gentoo.org/glsa/201503-04

Trust: 1.2

url:http://www.mandriva.com/security/advisories?name=mdvsa-2015:039

Trust: 1.2

url:http://packetstormsecurity.com/files/130171/exim-esmtp-ghost-denial-of-service.html

Trust: 1.2

url:http://packetstormsecurity.com/files/130768/emc-secure-remote-services-ghost-sql-injection-command-injection.html

Trust: 1.2

url:http://packetstormsecurity.com/files/130974/exim-ghost-glibc-gethostbyname-buffer-overflow.html

Trust: 1.2

url:http://packetstormsecurity.com/files/153278/wago-852-industrial-managed-switch-series-code-execution-hardcoded-credentials.html

Trust: 1.2

url:http://packetstormsecurity.com/files/164014/moxa-command-injection-cross-site-scripting-vulnerable-software.html

Trust: 1.2

url:http://packetstormsecurity.com/files/167552/nexans-ftto-gigaswitch-outdated-components-hardcoded-backdoor.html

Trust: 1.2

url:https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability

Trust: 1.2

url:https://www.arista.com/en/support/advisories-notices/security-advisories/1053-security-advisory-9

Trust: 1.2

url:http://www.openwall.com/lists/oss-security/2021/05/04/7

Trust: 1.2

url:http://rhn.redhat.com/errata/rhsa-2015-0126.html

Trust: 1.2

url:http://www.securitytracker.com/id/1032909

Trust: 1.2

url:http://secunia.com/advisories/62517

Trust: 1.2

url:http://secunia.com/advisories/62640

Trust: 1.2

url:http://secunia.com/advisories/62667

Trust: 1.2

url:http://secunia.com/advisories/62680

Trust: 1.2

url:http://secunia.com/advisories/62681

Trust: 1.2

url:http://secunia.com/advisories/62688

Trust: 1.2

url:http://secunia.com/advisories/62690

Trust: 1.2

url:http://secunia.com/advisories/62691

Trust: 1.2

url:http://secunia.com/advisories/62692

Trust: 1.2

url:http://secunia.com/advisories/62698

Trust: 1.2

url:http://secunia.com/advisories/62715

Trust: 1.2

url:http://secunia.com/advisories/62758

Trust: 1.2

url:http://secunia.com/advisories/62812

Trust: 1.2

url:http://secunia.com/advisories/62813

Trust: 1.2

url:http://secunia.com/advisories/62816

Trust: 1.2

url:http://secunia.com/advisories/62865

Trust: 1.2

url:http://secunia.com/advisories/62870

Trust: 1.2

url:http://secunia.com/advisories/62871

Trust: 1.2

url:http://secunia.com/advisories/62879

Trust: 1.2

url:http://secunia.com/advisories/62883

Trust: 1.2

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10671

Trust: 1.1

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10100

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=142721102728110&w=2

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=142781412222323&w=2

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=142722450701342&w=2

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=142296726407499&w=2

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=143145428124857&w=2

Trust: 1.1

url:http://www.openwall.com/lists/oss-security/2015/01/27/9

Trust: 0.8

url:https://security-tracker.debian.org/tracker/cve-2015-0235

Trust: 0.8

url:https://rhn.redhat.com/errata/rhsa-2015-0099.html

Trust: 0.8

url:http://lists.suse.com/pipermail/sle-security-updates/2015-january/001186.html

Trust: 0.8

url:http://www.slackware.com/security/list.php?l=slackware-security&y=2015

Trust: 0.8

url:https://wiki.ubuntu.com/securityteam/knowledgebase/ghost

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2015-0235

Trust: 0.7

url:https://access.redhat.com/security/cve/cve-2015-0235

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2012-6656

Trust: 0.2

url:http://www.debian.org/security/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-1914

Trust: 0.2

url:https://kb.juniper.net/infocenter/index?page=content&amp;id=jsa10671

Trust: 0.1

url:https://kc.mcafee.com/corporate/index?page=content&amp;id=sb10100

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=142296726407499&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=142781412222323&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=142722450701342&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=142721102728110&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=143145428124857&amp;w=2

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/787.html

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2015:0092

Trust: 0.1

url:https://usn.ubuntu.com/2485-1/

Trust: 0.1

url:https://www.exploit-db.com/exploits/35951/

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-0525

Trust: 0.1

url:https://www.securify.nl)

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-0524

Trust: 0.1

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_n

Trust: 0.1

url:http://www.hpe.com/support/security_bulletin_archive

Trust: 0.1

url:https://h10145.www1.hpe.com/sso/index.aspx?returnurl=..%2fdownloads%2fdow

Trust: 0.1

url:http://www.hpe.com/support/subscriber_choice

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-6657

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-3687

Trust: 0.1

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-3688

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-9322

Trust: 0.1

url:http://www.itrc.hp.com/service/cki/secbullarchive.do

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-5472

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-3673

Trust: 0.1

url:https://softwaresupport.hp.com/group/softwaresupport/search-

Trust: 0.1

url:http://h30046.www3.hp.com/subsignin.php

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-6410

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-5471

Trust: 0.1

url:http://h30046.www3.hp.com/driveralertprofile.php?

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-6040

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-7817

Trust: 0.1

url:http://www.debian.org/security/faq

Trust: 0.1

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.1

url:https://bugzilla.redhat.com/):

Trust: 0.1

url:https://access.redhat.com/security/team/key/

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#critical

Trust: 0.1

url:https://access.redhat.com/articles/11258

Trust: 0.1

url:https://access.redhat.com/security/team/contact/

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2015-0092.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3405

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-4458

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-4332

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3406

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-4458

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-4788

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-4237

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-6656

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2207

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0242

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201503-04.xml

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-4237

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4412

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3404

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-4332

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-4788

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-4424

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0235

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-3406

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1914

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-3405

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3480

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-2207

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-4043

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-4043

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0242

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-3404

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-4412

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-3480

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4424

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-39278

Trust: 0.1

url:https://www.moxa.com/en/support/product-support/security-advisory/oncell-g3470a-wdr-3124a-cellular-gateways-router-vulnerabilities

Trust: 0.1

url:https://www.moxa.com/en/about-us/corporate-responsibility

Trust: 0.1

url:https://seclists.org/oss-sec/2015/q1/274.

Trust: 0.1

url:https://sec-consult.com/contact/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-7423

Trust: 0.1

url:https://www.sec-consult.com

Trust: 0.1

url:https://sec-consult.com/vulnerability-lab/

Trust: 0.1

url:https://twitter.com/sec_consult

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-1234

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7547

Trust: 0.1

url:https://www.moxa.com/en/support/product-support/security-advisory/tap-323-wac-1001-2004-wireless-ap-bridge-client-vulnerabilities

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-39279

Trust: 0.1

url:http://blog.sec-consult.com

Trust: 0.1

url:https://www.moxa.com/

Trust: 0.1

url:https://sec-consult.com/career/

Trust: 0.1

url:http://192.168.1.1/forms/web_importtftp?servip=192.168.1.1&configpath=/&filename=name|`ping

Trust: 0.1

sources: CERT/CC: VU#967332 // VULHUB: VHN-78181 // VULMON: CVE-2015-0235 // PACKETSTORM: 130768 // PACKETSTORM: 134196 // PACKETSTORM: 131015 // PACKETSTORM: 130098 // PACKETSTORM: 130114 // PACKETSTORM: 130702 // PACKETSTORM: 164014 // NVD: CVE-2015-0235

CREDITS

HP

Trust: 0.2

sources: PACKETSTORM: 134196 // PACKETSTORM: 131015

SOURCES

db:CERT/CCid:VU#967332
db:VULHUBid:VHN-78181
db:VULMONid:CVE-2015-0235
db:PACKETSTORMid:130768
db:PACKETSTORMid:134196
db:PACKETSTORMid:131015
db:PACKETSTORMid:130098
db:PACKETSTORMid:130114
db:PACKETSTORMid:130702
db:PACKETSTORMid:164014
db:NVDid:CVE-2015-0235

LAST UPDATE DATE

2026-02-07T19:41:20.264000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#967332date:2015-10-22T00:00:00
db:VULHUBid:VHN-78181date:2021-11-17T00:00:00
db:VULMONid:CVE-2015-0235date:2024-02-14T00:00:00
db:NVDid:CVE-2015-0235date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CERT/CCid:VU#967332date:2015-01-28T00:00:00
db:VULHUBid:VHN-78181date:2015-01-28T00:00:00
db:VULMONid:CVE-2015-0235date:2015-01-28T00:00:00
db:PACKETSTORMid:130768date:2015-03-11T16:18:45
db:PACKETSTORMid:134196date:2015-11-03T16:53:42
db:PACKETSTORMid:131015date:2015-03-25T00:42:48
db:PACKETSTORMid:130098date:2015-01-27T18:04:25
db:PACKETSTORMid:130114date:2015-01-27T19:35:59
db:PACKETSTORMid:130702date:2015-03-09T20:15:21
db:PACKETSTORMid:164014date:2021-09-01T15:42:52
db:NVDid:CVE-2015-0235date:2015-01-28T19:59:00.063