ID

VAR-201501-0737


CVE

CVE-2015-0235


TITLE

GNU C Library (glibc) __nss_hostname_digits_dots() function vulnerable to buffer overflow

Trust: 1.6

sources: CERT/CC: VU#967332 // CERT/CC: VU#967332

DESCRIPTION

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST.". This vulnerability has been assigned CVE-2015-0235, and is referred to in the media by the name "GHOST". This vulnerability has been assigned CVE-2015-0235, and is referred to in the media by the name "GHOST". glibc The library contains a buffer overflow vulnerability. glibc Library vulnerable to buffer overflow (CWE-788) there is. The crafted host name gethostbyname Passing to the argument of a function such as will cause a buffer overflow. CWE-788: Access of Memory Location After End of Buffer http://cwe.mitre.org/data/definitions/788.html In addition, National Vulnerability Database (NVD) Then CWE-119 Published as. CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer http://cwe.mitre.org/data/definitions/119.htmlArbitrary code execution or denial of service by a remote third party (DoS) Or an attack may be made. Please update or upgrade to one of the following versions or subsequent. Release Date: 2015-02-02 Last Updated: 2015-02-02 Potential Security Impact: Remote execution of arbitrary code Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY A potential security vulnerability has been identified with HP IceWall SSO Dfw using glibc. This vulnerability could be used to remotely execute arbitrary code. References: CVE-2015-0235 - Buffer Errors (CWE-119) SSRT101906 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. HP IceWall SSO Dfw v8.0, v8.0 R1, v8.0 R2, v8.0 R3 BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2015-0235 (AV:N/AC:L/Au:N/C:C/I:C/A:C) 10.0 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION HP recommends the following software updates and workaround instructions to resolve this vulnerability for HP IceWall SSO Dfw. The glibc updates are available for RHEL4, RHEL5, and RHEL6 at: https://access.redhat.com/security/cve/CVE-2015-0235 WORKAROUND INSTRUCTIONS HP recommends following this information after applying the updates to protect against potential risk for the specified HP IceWall products. HP IceWall SSO Dfw The AGENT_PERMIT configuration parameter allows Dfw to restrict requests from the Agent (another module) by using one of following methods: IP (IP address), HOST(host name) and DOMAIN (domain name). If possible, do not specify the "IP" value as the evaluation method in setting AGENT_PERMIT. Instead, use "HOST" or "DOMAIN". Note: The HP IceWall product is only available in Japan. HISTORY Version:1 (rev.1) - 2 February 2015 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins Security Bulletin Archive: A list of recently released Security Bulletins is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/ Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. 3C = 3COM 3P = 3rd Party Software GN = HP General Software HF = HP Hardware and Firmware MP = MPE/iX MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PI = Printing and Imaging PV = ProCurve ST = Storage Software TU = Tru64 UNIX UX = HP-UX Copyright 2015 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Critical: glibc security update Advisory ID: RHSA-2015:0101-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2015-0101.html Issue date: 2015-01-28 CVE Names: CVE-2015-0235 ===================================================================== 1. Summary: Updated glibc packages that fix one security issue are now available for Red Hat Enterprise Linux 4 Extended Life Cycle Support. Red Hat Product Security has rated this update as having Critical security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (v. 4 ELS) - i386, ia64, x86_64 Red Hat Enterprise Linux ES (v. 4 ELS) - i386, ia64, x86_64 3. Description: The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the Name Server Caching Daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. A remote attacker able to make an application call either of these functions could use this flaw to execute arbitrary code with the permissions of the user running the application. (CVE-2015-0235) Red Hat would like to thank Qualys for reporting this issue. All glibc users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Package List: Red Hat Enterprise Linux AS (v. 4 ELS): Source: glibc-2.3.4-2.57.el4.2.src.rpm i386: glibc-2.3.4-2.57.el4.2.i386.rpm glibc-2.3.4-2.57.el4.2.i686.rpm glibc-common-2.3.4-2.57.el4.2.i386.rpm glibc-debuginfo-2.3.4-2.57.el4.2.i386.rpm glibc-debuginfo-2.3.4-2.57.el4.2.i686.rpm glibc-debuginfo-common-2.3.4-2.57.el4.2.i386.rpm glibc-devel-2.3.4-2.57.el4.2.i386.rpm glibc-headers-2.3.4-2.57.el4.2.i386.rpm glibc-profile-2.3.4-2.57.el4.2.i386.rpm glibc-utils-2.3.4-2.57.el4.2.i386.rpm nptl-devel-2.3.4-2.57.el4.2.i386.rpm nptl-devel-2.3.4-2.57.el4.2.i686.rpm nscd-2.3.4-2.57.el4.2.i386.rpm ia64: glibc-2.3.4-2.57.el4.2.i686.rpm glibc-2.3.4-2.57.el4.2.ia64.rpm glibc-common-2.3.4-2.57.el4.2.ia64.rpm glibc-debuginfo-2.3.4-2.57.el4.2.i686.rpm glibc-debuginfo-2.3.4-2.57.el4.2.ia64.rpm glibc-debuginfo-common-2.3.4-2.57.el4.2.i386.rpm glibc-devel-2.3.4-2.57.el4.2.ia64.rpm glibc-headers-2.3.4-2.57.el4.2.ia64.rpm glibc-profile-2.3.4-2.57.el4.2.ia64.rpm glibc-utils-2.3.4-2.57.el4.2.ia64.rpm nptl-devel-2.3.4-2.57.el4.2.ia64.rpm nscd-2.3.4-2.57.el4.2.ia64.rpm x86_64: glibc-2.3.4-2.57.el4.2.i686.rpm glibc-2.3.4-2.57.el4.2.x86_64.rpm glibc-common-2.3.4-2.57.el4.2.x86_64.rpm glibc-debuginfo-2.3.4-2.57.el4.2.i386.rpm glibc-debuginfo-2.3.4-2.57.el4.2.i686.rpm glibc-debuginfo-2.3.4-2.57.el4.2.x86_64.rpm glibc-debuginfo-common-2.3.4-2.57.el4.2.i386.rpm glibc-devel-2.3.4-2.57.el4.2.i386.rpm glibc-devel-2.3.4-2.57.el4.2.x86_64.rpm glibc-headers-2.3.4-2.57.el4.2.x86_64.rpm glibc-profile-2.3.4-2.57.el4.2.x86_64.rpm glibc-utils-2.3.4-2.57.el4.2.x86_64.rpm nptl-devel-2.3.4-2.57.el4.2.x86_64.rpm nscd-2.3.4-2.57.el4.2.x86_64.rpm Red Hat Enterprise Linux ES (v. 4 ELS): Source: glibc-2.3.4-2.57.el4.2.src.rpm i386: glibc-2.3.4-2.57.el4.2.i386.rpm glibc-2.3.4-2.57.el4.2.i686.rpm glibc-common-2.3.4-2.57.el4.2.i386.rpm glibc-debuginfo-2.3.4-2.57.el4.2.i386.rpm glibc-debuginfo-2.3.4-2.57.el4.2.i686.rpm glibc-debuginfo-common-2.3.4-2.57.el4.2.i386.rpm glibc-devel-2.3.4-2.57.el4.2.i386.rpm glibc-headers-2.3.4-2.57.el4.2.i386.rpm glibc-profile-2.3.4-2.57.el4.2.i386.rpm glibc-utils-2.3.4-2.57.el4.2.i386.rpm nptl-devel-2.3.4-2.57.el4.2.i386.rpm nptl-devel-2.3.4-2.57.el4.2.i686.rpm nscd-2.3.4-2.57.el4.2.i386.rpm ia64: glibc-debuginfo-common-2.3.4-2.57.el4.2.i386.rpm x86_64: glibc-2.3.4-2.57.el4.2.i686.rpm glibc-2.3.4-2.57.el4.2.x86_64.rpm glibc-common-2.3.4-2.57.el4.2.x86_64.rpm glibc-debuginfo-2.3.4-2.57.el4.2.i386.rpm glibc-debuginfo-2.3.4-2.57.el4.2.i686.rpm glibc-debuginfo-2.3.4-2.57.el4.2.x86_64.rpm glibc-debuginfo-common-2.3.4-2.57.el4.2.i386.rpm glibc-devel-2.3.4-2.57.el4.2.i386.rpm glibc-devel-2.3.4-2.57.el4.2.x86_64.rpm glibc-headers-2.3.4-2.57.el4.2.x86_64.rpm glibc-profile-2.3.4-2.57.el4.2.x86_64.rpm glibc-utils-2.3.4-2.57.el4.2.x86_64.rpm nptl-devel-2.3.4-2.57.el4.2.x86_64.rpm nscd-2.3.4-2.57.el4.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-0235 https://access.redhat.com/security/updates/classification/#critical 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFUyRwbXlSAg2UNWIIRAnx8AJ94LYbxTEFIpPLiN/L5Wg+RHu8sewCfU4Gq q+5AuvegeRJa0LimEFiDjZE= =l1Y9 -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201503-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GNU C Library: Multiple vulnerabilities Date: March 08, 2015 Bugs: #431218, #434408, #454862, #464634, #477330, #480734, #484646, #488084, #489234, #501196, #513090, #521930, #537990 ID: 201503-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been found in GNU C Library, the worst of which allowing a local attacker to execute arbitrary code or cause a Denial of Service . Background ========== The GNU C library is the standard C library used by Gentoo Linux systems. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-libs/glibc < 2.19-r1 >= 2.19-r1 Description =========== Multiple vulnerabilities have been discovered in the GNU C Library. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All glibc users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sys-libs/glibc-2.19-r1" References ========== [ 1 ] CVE-2012-3404 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3404 [ 2 ] CVE-2012-3405 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3405 [ 3 ] CVE-2012-3406 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3406 [ 4 ] CVE-2012-3480 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3480 [ 5 ] CVE-2012-4412 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4412 [ 6 ] CVE-2012-4424 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4424 [ 7 ] CVE-2012-6656 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-6656 [ 8 ] CVE-2013-0242 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0242 [ 9 ] CVE-2013-1914 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1914 [ 10 ] CVE-2013-2207 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2207 [ 11 ] CVE-2013-4237 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4237 [ 12 ] CVE-2013-4332 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4332 [ 13 ] CVE-2013-4458 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4458 [ 14 ] CVE-2013-4788 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4788 [ 15 ] CVE-2014-4043 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-4043 [ 16 ] CVE-2015-0235 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0235 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201503-04.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/glibc-2.17-i486-10_slack14.1.txz: Rebuilt. This flaw could allow local or remote attackers to take control of a machine running a vulnerable version of glibc. Thanks to Qualys for discovering this issue (also known as the GHOST vulnerability.) For more information, see: https://www.qualys.com/research/security-advisories/GHOST-CVE-2015-0235.txt http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0235 (* Security fix *) patches/packages/glibc-i18n-2.17-i486-10_slack14.1.txz: Rebuilt. patches/packages/glibc-profile-2.17-i486-10_slack14.1.txz: Rebuilt. patches/packages/glibc-solibs-2.17-i486-10_slack14.1.txz: Rebuilt. patches/packages/glibc-zoneinfo-2014j-noarch-1.txz: Upgraded. Upgraded to tzcode2014j and tzdata2014j. +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated packages for Slackware 13.0: ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/glibc-2.9-i486-7_slack13.0.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/glibc-i18n-2.9-i486-7_slack13.0.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/glibc-profile-2.9-i486-7_slack13.0.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/glibc-solibs-2.9-i486-7_slack13.0.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/glibc-zoneinfo-2014j-noarch-1.txz Updated packages for Slackware x86_64 13.0: ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/glibc-2.9-x86_64-7_slack13.0.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/glibc-i18n-2.9-x86_64-7_slack13.0.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/glibc-profile-2.9-x86_64-7_slack13.0.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/glibc-solibs-2.9-x86_64-7_slack13.0.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/glibc-zoneinfo-2014j-noarch-1.txz Updated packages for Slackware 13.1: ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/glibc-2.11.1-i486-9_slack13.1.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/glibc-i18n-2.11.1-i486-9_slack13.1.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/glibc-profile-2.11.1-i486-9_slack13.1.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/glibc-solibs-2.11.1-i486-9_slack13.1.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/glibc-zoneinfo-2014j-noarch-1.txz Updated packages for Slackware x86_64 13.1: ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/glibc-2.11.1-x86_64-9_slack13.1.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/glibc-i18n-2.11.1-x86_64-9_slack13.1.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/glibc-profile-2.11.1-x86_64-9_slack13.1.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/glibc-solibs-2.11.1-x86_64-9_slack13.1.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/glibc-zoneinfo-2014j-noarch-1.txz Updated packages for Slackware 13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/glibc-2.13-i486-8_slack13.37.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/glibc-i18n-2.13-i486-8_slack13.37.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/glibc-profile-2.13-i486-8_slack13.37.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/glibc-solibs-2.13-i486-8_slack13.37.txz ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/glibc-zoneinfo-2014j-noarch-1.txz Updated packages for Slackware x86_64 13.37: ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/glibc-2.13-x86_64-8_slack13.37.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/glibc-i18n-2.13-x86_64-8_slack13.37.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/glibc-profile-2.13-x86_64-8_slack13.37.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/glibc-solibs-2.13-x86_64-8_slack13.37.txz ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/glibc-zoneinfo-2014j-noarch-1.txz Updated packages for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/glibc-2.15-i486-9_slack14.0.txz ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/glibc-i18n-2.15-i486-9_slack14.0.txz ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/glibc-profile-2.15-i486-9_slack14.0.txz ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/glibc-solibs-2.15-i486-9_slack14.0.txz ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/glibc-zoneinfo-2014j-noarch-1.txz Updated packages for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/glibc-2.15-x86_64-9_slack14.0.txz ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/glibc-i18n-2.15-x86_64-9_slack14.0.txz ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/glibc-profile-2.15-x86_64-9_slack14.0.txz ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/glibc-solibs-2.15-x86_64-9_slack14.0.txz ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/glibc-zoneinfo-2014j-noarch-1.txz Updated packages for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/glibc-2.17-i486-10_slack14.1.txz ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/glibc-i18n-2.17-i486-10_slack14.1.txz ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/glibc-profile-2.17-i486-10_slack14.1.txz ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/glibc-solibs-2.17-i486-10_slack14.1.txz ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/glibc-zoneinfo-2014j-noarch-1.txz Updated packages for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/glibc-2.17-x86_64-10_slack14.1.txz ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/glibc-i18n-2.17-x86_64-10_slack14.1.txz ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/glibc-profile-2.17-x86_64-10_slack14.1.txz ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/glibc-solibs-2.17-x86_64-10_slack14.1.txz ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/glibc-zoneinfo-2014j-noarch-1.txz Updated packages for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/a/glibc-solibs-2.20-i486-2.txz ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/a/glibc-zoneinfo-2014j-noarch-1.txz ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/glibc-2.20-i486-2.txz ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/glibc-i18n-2.20-i486-2.txz ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/glibc-profile-2.20-i486-2.txz Updated packages for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/a/glibc-solibs-2.20-x86_64-2.txz ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/a/glibc-zoneinfo-2014j-noarch-1.txz ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/glibc-2.20-x86_64-2.txz ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/glibc-i18n-2.20-x86_64-2.txz ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/glibc-profile-2.20-x86_64-2.txz MD5 signatures: +-------------+ Slackware 13.0 packages: 41402c65ebdef4b022c799131556ef7e glibc-2.9-i486-7_slack13.0.txz 7095e3cd743af0179ea14b9bff81e3f4 glibc-i18n-2.9-i486-7_slack13.0.txz 901d50b809ed84837ff45b2ca7838bb3 glibc-profile-2.9-i486-7_slack13.0.txz 421a711b7cf1be2df2421ae5cd50b217 glibc-solibs-2.9-i486-7_slack13.0.txz 61278ba5a904a7474e9b0b64b0daab97 glibc-zoneinfo-2014j-noarch-1.txz Slackware x86_64 13.0 packages: d4266628a8db63751f3f55b8bc2e2162 glibc-2.9-x86_64-7_slack13.0.txz b6161a0e23da771c5c6903605e49e403 glibc-i18n-2.9-x86_64-7_slack13.0.txz b8026d61e3849cce26539def0b665ca3 glibc-profile-2.9-x86_64-7_slack13.0.txz 1f7f4cf57d44d75d4ef2786152f33403 glibc-solibs-2.9-x86_64-7_slack13.0.txz 61278ba5a904a7474e9b0b64b0daab97 glibc-zoneinfo-2014j-noarch-1.txz Slackware 13.1 packages: 03e0d0224efe8bc794b5be0454612a1e glibc-2.11.1-i486-9_slack13.1.txz fabbdd8d7f14667c7a2dc7ede87b5510 glibc-i18n-2.11.1-i486-9_slack13.1.txz 1c1d86a9dabe329c3d30796188b66ebe glibc-profile-2.11.1-i486-9_slack13.1.txz e2ebe08bb02550c69202a6f973ef7e47 glibc-solibs-2.11.1-i486-9_slack13.1.txz 61278ba5a904a7474e9b0b64b0daab97 glibc-zoneinfo-2014j-noarch-1.txz Slackware x86_64 13.1 packages: c00de492a4842e3a86101028e8cc03f0 glibc-2.11.1-x86_64-9_slack13.1.txz 9657c55f39b233333e48d08acee9ed78 glibc-i18n-2.11.1-x86_64-9_slack13.1.txz ada2d7f7b7ffdfd7a4407696ad714e48 glibc-profile-2.11.1-x86_64-9_slack13.1.txz b3c393e74aafbb5276cea1217dfcd1aa glibc-solibs-2.11.1-x86_64-9_slack13.1.txz 61278ba5a904a7474e9b0b64b0daab97 glibc-zoneinfo-2014j-noarch-1.txz Slackware 13.37 packages: 16615e6ef8311b928e3a05e0b7f3e505 glibc-2.13-i486-8_slack13.37.txz 319dfc0cbdaf8410981195fffb1371c6 glibc-i18n-2.13-i486-8_slack13.37.txz 6964339495ab981d17ba27cd5878a400 glibc-profile-2.13-i486-8_slack13.37.txz 1834abd11fab02725e897040bbead56f glibc-solibs-2.13-i486-8_slack13.37.txz 61278ba5a904a7474e9b0b64b0daab97 glibc-zoneinfo-2014j-noarch-1.txz Slackware x86_64 13.37 packages: 1753003d261831ac235445e23a9f9870 glibc-2.13-x86_64-8_slack13.37.txz 8aa103984bb2cb293072a022dd9144f2 glibc-i18n-2.13-x86_64-8_slack13.37.txz a56e90a34eec8f60e265c45d05490a57 glibc-profile-2.13-x86_64-8_slack13.37.txz c6f684ea049e4091b96d15606eb454d1 glibc-solibs-2.13-x86_64-8_slack13.37.txz 61278ba5a904a7474e9b0b64b0daab97 glibc-zoneinfo-2014j-noarch-1.txz Slackware 14.0 packages: a2fadb666bfdf5c7c4c9792cbf34785d glibc-2.15-i486-9_slack14.0.txz 3b3626f4a170a603af36ca60c7840fa6 glibc-i18n-2.15-i486-9_slack14.0.txz ad237d138bb874e57c4080071d27e798 glibc-profile-2.15-i486-9_slack14.0.txz f07d37e52014cec80e43d883eda516ae glibc-solibs-2.15-i486-9_slack14.0.txz 61278ba5a904a7474e9b0b64b0daab97 glibc-zoneinfo-2014j-noarch-1.txz Slackware x86_64 14.0 packages: a5d02d71a230b6daa39d2ebefd8a6548 glibc-2.15-x86_64-9_slack14.0.txz 62c30b615e38ba63cafb8053383eabde glibc-i18n-2.15-x86_64-9_slack14.0.txz 152d094ab6bc4c7f763dd4ad1a53784c glibc-profile-2.15-x86_64-9_slack14.0.txz b256163bb179d1aebfda5f45270a0580 glibc-solibs-2.15-x86_64-9_slack14.0.txz 61278ba5a904a7474e9b0b64b0daab97 glibc-zoneinfo-2014j-noarch-1.txz Slackware 14.1 packages: 8f2fb91bb39d8a1db3bd6510295e6b1e glibc-2.17-i486-10_slack14.1.txz 8d179820a827a4dce028b57d3fa39237 glibc-i18n-2.17-i486-10_slack14.1.txz 19a4824c6ff8792a1166a38ceff824e0 glibc-profile-2.17-i486-10_slack14.1.txz 417dede2ae464059002b6fcc2048f942 glibc-solibs-2.17-i486-10_slack14.1.txz 61278ba5a904a7474e9b0b64b0daab97 glibc-zoneinfo-2014j-noarch-1.txz Slackware x86_64 14.1 packages: 490ce11a13439e30ff312769cc4fabb1 glibc-2.17-x86_64-10_slack14.1.txz cd145e0d6a12b15d5282d7d1b3de92ed glibc-i18n-2.17-x86_64-10_slack14.1.txz 93aea777dd41dc1c631dce1cf252bf14 glibc-profile-2.17-x86_64-10_slack14.1.txz 6b759039a5b3f8c88b3753e722ded78e glibc-solibs-2.17-x86_64-10_slack14.1.txz 61278ba5a904a7474e9b0b64b0daab97 glibc-zoneinfo-2014j-noarch-1.txz Slackware -current packages: 395d4ad5fb71c4a56a500c3e51d07c8b a/glibc-solibs-2.20-i486-2.txz 61278ba5a904a7474e9b0b64b0daab97 a/glibc-zoneinfo-2014j-noarch-1.txz 3ca2827446e66d0d2d0e0bc8c55ba1ed l/glibc-2.20-i486-2.txz 94105b1a10c42ce0995f8ace6b4f06a8 l/glibc-i18n-2.20-i486-2.txz fcc2ad4f5aad3a7d704d708a170c5351 l/glibc-profile-2.20-i486-2.txz Slackware x86_64 -current packages: 25129dd9dfed8a8e834c87ba40c1ef17 a/glibc-solibs-2.20-x86_64-2.txz 61278ba5a904a7474e9b0b64b0daab97 a/glibc-zoneinfo-2014j-noarch-1.txz b8ff5e308769d8e4eddccd9940058d5c l/glibc-2.20-x86_64-2.txz 8c3db9286aa93346d25ffad38178137b l/glibc-i18n-2.20-x86_64-2.txz 21f2a62d975b433f570cd5129cdc21fb l/glibc-profile-2.20-x86_64-2.txz Installation instructions: +------------------------+ Upgrade the packages as root: # upgradepkg glibc-* +-----+ Slackware Linux Security Team http://slackware.com/gpg-key security@slackware.com +------------------------------------------------------------------------+ | To leave the slackware-security mailing list: | +------------------------------------------------------------------------+ | Send an email to majordomo@slackware.com with this text in the body of | | the email message: | | | | unsubscribe slackware-security | | | | You will get a confirmation message back containing instructions to | | complete the process. Please do not reply to this email address

Trust: 3.69

sources: NVD: CVE-2015-0235 // CERT/CC: VU#967332 // CERT/CC: VU#967332 // JVNDB: JVNDB-2015-001251 // VULHUB: VHN-78181 // PACKETSTORM: 134196 // PACKETSTORM: 130216 // PACKETSTORM: 131214 // PACKETSTORM: 130135 // PACKETSTORM: 130702 // PACKETSTORM: 130163

AFFECTED PRODUCTS

vendor:oraclemodel:communications policy managementscope:eqversion:10.4.1

Trust: 1.8

vendor:oraclemodel:communications policy managementscope:eqversion:9.7.3

Trust: 1.8

vendor:oraclemodel:communications policy managementscope:eqversion:9.9.1

Trust: 1.8

vendor:arch linuxmodel: - scope: - version: -

Trust: 1.6

vendor:blue coatmodel: - scope: - version: -

Trust: 1.6

vendor:ciscomodel: - scope: - version: -

Trust: 1.6

vendor:citrixmodel: - scope: - version: -

Trust: 1.6

vendor:debian gnu linuxmodel: - scope: - version: -

Trust: 1.6

vendor:f5model: - scope: - version: -

Trust: 1.6

vendor:gentoo linuxmodel: - scope: - version: -

Trust: 1.6

vendor:junipermodel: - scope: - version: -

Trust: 1.6

vendor:necmodel: - scope: - version: -

Trust: 1.6

vendor:netappmodel: - scope: - version: -

Trust: 1.6

vendor:openwall gnu linuxmodel: - scope: - version: -

Trust: 1.6

vendor:red hatmodel: - scope: - version: -

Trust: 1.6

vendor:suse linuxmodel: - scope: - version: -

Trust: 1.6

vendor:slackware linuxmodel: - scope: - version: -

Trust: 1.6

vendor:ubuntumodel: - scope: - version: -

Trust: 1.6

vendor:opensusemodel: - scope: - version: -

Trust: 1.6

vendor:ibmmodel:pureapplication systemscope:eqversion:1.1.0.0

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:7.0

Trust: 1.0

vendor:phpmodel:phpscope:gteversion:5.5.0

Trust: 1.0

vendor:oraclemodel:communications webrtc session controllerscope:eqversion:7.1

Trust: 1.0

vendor:phpmodel:phpscope:ltversion:5.4.38

Trust: 1.0

vendor:redhatmodel:virtualizationscope:eqversion:6.0

Trust: 1.0

vendor:applemodel:mac os xscope:ltversion:10.11.1

Trust: 1.0

vendor:oraclemodel:vm virtualboxscope:ltversion:5.1.24

Trust: 1.0

vendor:oraclemodel:communications policy managementscope:eqversion:12.1.1

Trust: 1.0

vendor:oraclemodel:communications webrtc session controllerscope:eqversion:7.2

Trust: 1.0

vendor:gnumodel:glibcscope:ltversion:2.18

Trust: 1.0

vendor:oraclemodel:communications user data repositoryscope:lteversion:10.0.1

Trust: 1.0

vendor:oraclemodel:exalogic infrastructurescope:eqversion:1.0

Trust: 1.0

vendor:oraclemodel:communications webrtc session controllerscope:eqversion:7.0

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:8.0

Trust: 1.0

vendor:oraclemodel:communications eagle application processorscope:eqversion:16.0

Trust: 1.0

vendor:oraclemodel:communications session border controllerscope:eqversion:7.2.0

Trust: 1.0

vendor:phpmodel:phpscope:ltversion:5.6.6

Trust: 1.0

vendor:oraclemodel:communications eagle lnp application processorscope:eqversion:10.0

Trust: 1.0

vendor:oraclemodel:communications session border controllerscope:ltversion:7.2.0

Trust: 1.0

vendor:phpmodel:phpscope:ltversion:5.5.22

Trust: 1.0

vendor:oraclemodel:communications policy managementscope:eqversion:11.5

Trust: 1.0

vendor:oraclemodel:linuxscope:eqversion:5

Trust: 1.0

vendor:ibmmodel:pureapplication systemscope:eqversion:1.0.0.0

Trust: 1.0

vendor:gnumodel:glibcscope:gteversion:2.0

Trust: 1.0

vendor:phpmodel:phpscope:gteversion:5.4.0

Trust: 1.0

vendor:oraclemodel:communications application session controllerscope:ltversion:3.7.1

Trust: 1.0

vendor:oraclemodel:linuxscope:eqversion:7

Trust: 1.0

vendor:ibmmodel:pureapplication systemscope:eqversion:2.0.0.0

Trust: 1.0

vendor:oraclemodel:communications lsmsscope:eqversion:13.1

Trust: 1.0

vendor:phpmodel:phpscope:gteversion:5.6.0

Trust: 1.0

vendor:oraclemodel:exalogic infrastructurescope:eqversion:2.0

Trust: 1.0

vendor:oraclemodel:communications user data repositoryscope:gteversion:10.0.0

Trust: 1.0

vendor:ibmmodel:security access manager for enterprise single sign-onscope:eqversion:8.2

Trust: 1.0

vendor:oraclemodel:communications session border controllerscope:eqversion:8.0.0

Trust: 1.0

vendor:gnumodel:c libraryscope:lteversion:(glibc) 2.2 from 2.17

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.10 to 10.10.3 (ht204942)

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.10.5 (ht205375)

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.11 (ht205375)

Trust: 0.8

vendor:applemodel:mac os xscope:ltversion:10.6.8 thats all 10.11 (ht205267)

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.9.5 (ht204942/ht205375)

Trust: 0.8

vendor:oraclemodel:integrated lights out managerscope:ltversion:(sun system firmware) 8.7.2.b

Trust: 0.8

vendor:oraclemodel:integrated lights out managerscope:ltversion:(sun system firmware) 9.4.2e

Trust: 0.8

vendor:oraclemodel:communications applicationsscope:eqversion:of oracle communications eagle application processor 16.0

Trust: 0.8

vendor:oraclemodel:communications applicationsscope:eqversion:of oracle communications eagle lnp application processor 10.0

Trust: 0.8

vendor:oraclemodel:communications applicationsscope:eqversion:of oracle communications lsms 13.1

Trust: 0.8

vendor:oraclemodel:communications applicationsscope:ltversion:of oracle communications session border controller 7.2.0m4

Trust: 0.8

vendor:oraclemodel:communications policy managementscope:lteversion:12.1.1

Trust: 0.8

vendor:oraclemodel:ethernet switchscope:ltversion:es2-64 1.9.1.2

Trust: 0.8

vendor:oraclemodel:ethernet switchscope:ltversion:es2-72 1.9.1.2

Trust: 0.8

vendor:oraclemodel:fs1-2 flash storage systemscope:eqversion:6.1

Trust: 0.8

vendor:oraclemodel:fs1-2 flash storage systemscope:eqversion:6.2

Trust: 0.8

vendor:oraclemodel:fs1-2 flash storage systemscope:eqversion:6.3

Trust: 0.8

vendor:oraclemodel:fusion middlewarescope:eqversion:of oracle exalogic infrastructure 1.x

Trust: 0.8

vendor:oraclemodel:fusion middlewarescope:eqversion:of oracle exalogic infrastructure 2.x

Trust: 0.8

vendor:oraclemodel:sun systems products suitescope:eqversion:of cisco mds fiber channel switch 5.2

Trust: 0.8

vendor:oraclemodel:sun systems products suitescope:eqversion:of cisco mds fiber channel switch 6.2

Trust: 0.8

vendor:oraclemodel:sun systems products suitescope:ltversion:of sun data center infiniband switch 36 2.2.2

Trust: 0.8

vendor:oraclemodel:sun systems products suitescope:ltversion:of sun network qdr infiniband gateway switch 2.2.2

Trust: 0.8

vendor:oraclemodel:switchscope:ltversion:es1-24 1.3.1

Trust: 0.8

vendor:oraclemodel:sparc enterprise m3000 serverscope: - version: -

Trust: 0.8

vendor:oraclemodel:sparc enterprise m4000 serverscope: - version: -

Trust: 0.8

vendor:oraclemodel:sparc enterprise m5000 serverscope: - version: -

Trust: 0.8

vendor:oraclemodel:sparc enterprise m8000 serverscope: - version: -

Trust: 0.8

vendor:oraclemodel:sparc enterprise m9000 serverscope: - version: -

Trust: 0.8

vendor:oraclemodel:sun blade 6000 ethernet switched nem 24p 10gescope:ltversion:1.2.2

Trust: 0.8

vendor:oraclemodel:sun network 10ge switch 72pscope:ltversion:1.2.2

Trust: 0.8

vendor:oraclemodel:xcpscope:ltversion:1120 (sparc enterprise m3000/m4000/m5000/m8000/m9000 server )

Trust: 0.8

vendor:oraclemodel:xcpscope:ltversion:2260 (fujitsu m10-1/m10-4/m10-4s server )

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:4 for x86 (32bit)

Trust: 0.8

vendor:cybertrustmodel:asianux serverscope:eqversion:4 for x86_64 (64bit)

Trust: 0.8

vendor:hewlett packardmodel:hp operations analyticsscope:eqversion:2.0

Trust: 0.8

vendor:hewlett packardmodel:hp operations analyticsscope:eqversion:2.1

Trust: 0.8

vendor:hewlett packardmodel:hp operations analyticsscope:eqversion:2.2

Trust: 0.8

vendor:necmodel:enterpriseidentitymanagerscope:eqversion:linux of the edition

Trust: 0.8

vendor:necmodel:securebranchscope:eqversion:3.2.x

Trust: 0.8

vendor:necmodel:securebranchscope:eqversion:relay server 3.2.x

Trust: 0.8

vendor:hitachimodel:ups management softwarescope:eqversion:powerchute network shutdown virtualization v3.2

Trust: 0.8

vendor:gnumodel:glibcscope:eqversion:2.15

Trust: 0.6

vendor:gnumodel:glibcscope:eqversion:2.16

Trust: 0.6

vendor:gnumodel:glibcscope:eqversion:2.13

Trust: 0.6

vendor:gnumodel:glibcscope:eqversion:2.12.1

Trust: 0.6

vendor:gnumodel:glibcscope:eqversion:2.14

Trust: 0.6

vendor:gnumodel:glibcscope:eqversion:2.14.1

Trust: 0.6

vendor:gnumodel:glibcscope:eqversion:2.12.2

Trust: 0.6

vendor:gnumodel:glibcscope:eqversion:2.11.2

Trust: 0.6

vendor:gnumodel:glibcscope:eqversion:2.17

Trust: 0.6

vendor:gnumodel:glibcscope:eqversion:2.12

Trust: 0.6

sources: CERT/CC: VU#967332 // CERT/CC: VU#967332 // CNNVD: CNNVD-201501-658 // JVNDB: JVNDB-2015-001251 // NVD: CVE-2015-0235

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2015-0235
value: HIGH

Trust: 2.4

nvd@nist.gov: CVE-2015-0235
value: HIGH

Trust: 1.0

CNNVD: CNNVD-201501-658
value: HIGH

Trust: 0.6

VULHUB: VHN-78181
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-0235
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

NVD: CVE-2015-0235
severity: HIGH
baseScore: 10.0
vectorString: NONE
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.6

VULHUB: VHN-78181
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#967332 // CERT/CC: VU#967332 // VULHUB: VHN-78181 // CNNVD: CNNVD-201501-658 // JVNDB: JVNDB-2015-001251 // NVD: CVE-2015-0235

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.1

problemtype:CWE-119

Trust: 0.9

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-78181 // JVNDB: JVNDB-2015-001251 // NVD: CVE-2015-0235

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 130135 // CNNVD: CNNVD-201501-658

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201501-658

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001251

EXPLOIT AVAILABILITY

sources: CERT/CC: VU#967332 // CERT/CC: VU#967332 // VULHUB: VHN-78181

PATCH

title:APPLE-SA-2015-10-21-4 OS X El Capitan 10.11.1 and Security Update 2015-007url:http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html

Trust: 0.8

title:APPLE-SA-2015-09-30-3 OS X El Capitan 10.11url:http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html

Trust: 0.8

title:APPLE-SA-2015-06-30-2 OS X Yosemite v10.10.4 and Security Update 2015-005url:http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html

Trust: 0.8

title:HT205375url:https://support.apple.com/en-us/HT205375

Trust: 0.8

title:HT205267url:https://support.apple.com/en-us/HT205267

Trust: 0.8

title:HT204942url:http://support.apple.com/en-us/HT204942

Trust: 0.8

title:HT204942url:http://support.apple.com/ja-jp/HT204942

Trust: 0.8

title:HT205375url:https://support.apple.com/ja-jp/HT205375

Trust: 0.8

title:HT205267url:http://support.apple.com/ja-jp/HT205267

Trust: 0.8

title:cisco-sa-20150128-ghosturl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150128-ghost

Trust: 0.8

title:DSA-3142url:https://www.debian.org/security/2015/dsa-3142

Trust: 0.8

title:HPSBGN03270 SSRT101937url:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c04577814

Trust: 0.8

title:HPSBHF03289 SSRT101953url:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c04602055

Trust: 0.8

title:1696526url:http://www-01.ibm.com/support/docview.wss?uid=swg21696526

Trust: 0.8

title:1696600url:http://www-01.ibm.com/support/docview.wss?uid=swg21696600

Trust: 0.8

title:1696602url:http://www-01.ibm.com/support/docview.wss?uid=swg21696602

Trust: 0.8

title:1696618url:http://www-01.ibm.com/support/docview.wss?uid=swg21696618

Trust: 0.8

title:1695860url:http://www-01.ibm.com/support/docview.wss?uid=swg21695860

Trust: 0.8

title:1695835url:http://www-01.ibm.com/support/docview.wss?uid=swg21695835

Trust: 0.8

title:1696243url:http://www-01.ibm.com/support/docview.wss?uid=swg21696243

Trust: 0.8

title:アライドテレシス株式会社からの情報url:http://jvn.jp/vu/JVNVU99234709/522154/index.html

Trust: 0.8

title:SB10100url:https://kc.mcafee.com/corporate/index?page=content&id=SB10100

Trust: 0.8

title:NV15-007url:http://jpn.nec.com/security-info/secinfo/nv15-007.html

Trust: 0.8

title:ELSA-2015-0090url:http://linux.oracle.com/errata/ELSA-2015-0090.html

Trust: 0.8

title:ELSA-2015-0092url:http://linux.oracle.com/errata/ELSA-2015-0092.html

Trust: 0.8

title:Oracle Critical Patch Update Advisory - October 2015url:http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html

Trust: 0.8

title:Text Form of Oracle Critical Patch Update - January 2016 Risk Matricesurl:http://www.oracle.com/technetwork/topics/security/cpujan2016verbose-2367956.html

Trust: 0.8

title:Text Form of Oracle Critical Patch Update - October 2015 Risk Matricesurl:http://www.oracle.com/technetwork/topics/security/cpuoct2015verbose-2367954.html

Trust: 0.8

title:Oracle Critical Patch Update Advisory - April 2015url:http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html

Trust: 0.8

title:Oracle Critical Patch Update Advisory - July 2016url:http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

Trust: 0.8

title:Text Form of Oracle Critical Patch Update - April 2015 Risk Matricesurl:http://www.oracle.com/technetwork/topics/security/cpuapr2015verbose-2365613.html

Trust: 0.8

title:Oracle Critical Patch Update Advisory - July 2015url:http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html

Trust: 0.8

title:Text Form of Oracle Critical Patch Update - July 2016 Risk Matricesurl:http://www.oracle.com/technetwork/topics/security/cpujul2016verbose-2881721.html

Trust: 0.8

title:Text Form of Oracle Critical Patch Update - July 2015 Risk Matricesurl:http://www.oracle.com/technetwork/topics/security/cpujul2015verbose-2367947.html

Trust: 0.8

title:Oracle Critical Patch Update Advisory - October 2016url:http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html

Trust: 0.8

title:Text Form of Oracle Critical Patch Update - October 2016 Risk Matricesurl:http://www.oracle.com/technetwork/security-advisory/cpuoct2016verbose-2881725.html

Trust: 0.8

title:Oracle Critical Patch Update Advisory - January 2016url:http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html

Trust: 0.8

title:Oracle Solaris Third Party Bulletin - April 2015url:http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html

Trust: 0.8

title:RHSA-2015:0126url:https://rhn.redhat.com/errata/RHSA-2015-0126.html

Trust: 0.8

title:RHSA-2015:0092url:https://rhn.redhat.com/errata/RHSA-2015-0092.html

Trust: 0.8

title:SA90url:https://bto.bluecoat.com/security-advisory/sa90

Trust: 0.8

title:January 2016 Critical Patch Update Releasedurl:https://blogs.oracle.com/security/entry/january_2016_critical_patch_update

Trust: 0.8

title:October 2015 Critical Patch Update Releasedurl:https://blogs.oracle.com/security/entry/october_2015_critical_patch_update

Trust: 0.8

title:July 2016 Critical Patch Update Releasedurl:http://blogs.oracle.com/security/entry/july_2016_critical_patch_update

Trust: 0.8

title:April 2015 Critical Patch Update Releasedurl:https://blogs.oracle.com/security/entry/april_2015_critical_patch_update

Trust: 0.8

title:July 2015 Critical Patch Update Releasedurl:https://blogs.oracle.com/security/entry/july_2015_critical_patch_update

Trust: 0.8

title:October 2016 Critical Patch Update Releasedurl:https://blogs.oracle.com/security/entry/october_2016_critical_patch_update

Trust: 0.8

title:JSA10671url:https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10671

Trust: 0.8

title:Vulnerabilities resolved in TRITON APX Version 8.0url:http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0

Trust: 0.8

title:121879url:https://www.sophos.com/en-us/support/knowledgebase/121879.aspx

Trust: 0.8

title:Sophos products and the GHOST vulnerability affecting Linuxurl:http://blogs.sophos.com/2015/01/29/sophos-products-and-the-ghost-vulnerability-affecting-linux/

Trust: 0.8

title:Bug 15014url:https://sourceware.org/bugzilla/show_bug.cgi?id=15014

Trust: 0.8

title:USN-2485-1url:http://www.ubuntu.com/usn/usn-2485-1/

Trust: 0.8

title:サーバ・クライアント製品 glibc(GNU C Library)の脆弱性((CVE-2015-0235) 通称GHOST)による影響についてurl:http://www.hitachi.co.jp/products/it/server/security/info/vulnerable/glibc_cve-2015-0235.html

Trust: 0.8

title:glibc (GHOST) の脆弱性 (CVE-2015-0235)url:https://users.miraclelinux.com/support/?q=node/433

Trust: 0.8

title:cisco-sa-20150128-ghosturl:http://www.cisco.com/cisco/web/support/JP/112/1128/1128229_cisco-sa-20150128-ghost-j.html

Trust: 0.8

title:株式会社バッファロー の告知ページurl:http://buffalo.jp/support_s/s20150327a.html

Trust: 0.8

title:TLSA-2015-3url:http://www.turbolinux.co.jp/security/2015/TLSA-2015-3j.html

Trust: 0.8

title:glibc-2.18url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=53554

Trust: 0.6

title:glibc-2.18url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=53556

Trust: 0.6

title:glibc-2.18url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=53555

Trust: 0.6

sources: CNNVD: CNNVD-201501-658 // JVNDB: JVNDB-2015-001251

EXTERNAL IDS

db:NVDid:CVE-2015-0235

Trust: 4.7

db:CERT/CCid:VU#967332

Trust: 2.4

db:BIDid:91787

Trust: 1.7

db:BIDid:72325

Trust: 1.7

db:PACKETSTORMid:167552

Trust: 1.7

db:PACKETSTORMid:164014

Trust: 1.7

db:PACKETSTORMid:130974

Trust: 1.7

db:PACKETSTORMid:153278

Trust: 1.7

db:PACKETSTORMid:130768

Trust: 1.7

db:PACKETSTORMid:130171

Trust: 1.7

db:SECUNIAid:62883

Trust: 1.7

db:SECUNIAid:62690

Trust: 1.7

db:SECUNIAid:62871

Trust: 1.7

db:SECUNIAid:62680

Trust: 1.7

db:SECUNIAid:62517

Trust: 1.7

db:SECUNIAid:62640

Trust: 1.7

db:SECUNIAid:62715

Trust: 1.7

db:SECUNIAid:62812

Trust: 1.7

db:SECUNIAid:62667

Trust: 1.7

db:SECUNIAid:62879

Trust: 1.7

db:SECUNIAid:62813

Trust: 1.7

db:SECUNIAid:62698

Trust: 1.7

db:SECUNIAid:62681

Trust: 1.7

db:SECUNIAid:62692

Trust: 1.7

db:SECUNIAid:62758

Trust: 1.7

db:SECUNIAid:62870

Trust: 1.7

db:SECUNIAid:62816

Trust: 1.7

db:SECUNIAid:62691

Trust: 1.7

db:SECUNIAid:62688

Trust: 1.7

db:SECUNIAid:62865

Trust: 1.7

db:JUNIPERid:JSA10671

Trust: 1.7

db:SECTRACKid:1032909

Trust: 1.7

db:MCAFEEid:SB10100

Trust: 1.7

db:SIEMENSid:SSA-994726

Trust: 1.7

db:OPENWALLid:OSS-SECURITY/2021/05/04/7

Trust: 1.7

db:OPENWALLid:OSS-SECURITY/2015/01/27/9

Trust: 1.6

db:JVNid:JVNVU92655282

Trust: 0.8

db:JVNid:JVNVU97220341

Trust: 0.8

db:JVNid:JVNVU99234709

Trust: 0.8

db:JVNDBid:JVNDB-2015-001251

Trust: 0.8

db:CNNVDid:CNNVD-201501-658

Trust: 0.7

db:CXSECURITYid:WLB-2022060049

Trust: 0.6

db:PACKETSTORMid:131214

Trust: 0.2

db:PACKETSTORMid:134196

Trust: 0.2

db:PACKETSTORMid:130216

Trust: 0.2

db:PACKETSTORMid:130135

Trust: 0.2

db:PACKETSTORMid:130163

Trust: 0.2

db:PACKETSTORMid:131867

Trust: 0.1

db:PACKETSTORMid:130115

Trust: 0.1

db:PACKETSTORMid:130100

Trust: 0.1

db:PACKETSTORMid:130134

Trust: 0.1

db:PACKETSTORMid:130099

Trust: 0.1

db:PACKETSTORMid:130114

Trust: 0.1

db:PACKETSTORMid:130333

Trust: 0.1

db:EXPLOIT-DBid:36421

Trust: 0.1

db:EXPLOIT-DBid:35951

Trust: 0.1

db:SEEBUGid:SSVID-89237

Trust: 0.1

db:VULHUBid:VHN-78181

Trust: 0.1

db:PACKETSTORMid:130702

Trust: 0.1

sources: CERT/CC: VU#967332 // CERT/CC: VU#967332 // VULHUB: VHN-78181 // PACKETSTORM: 134196 // PACKETSTORM: 130216 // PACKETSTORM: 131214 // PACKETSTORM: 130135 // PACKETSTORM: 130702 // PACKETSTORM: 130163 // CNNVD: CNNVD-201501-658 // JVNDB: JVNDB-2015-001251 // NVD: CVE-2015-0235

REFERENCES

url:https://www.qualys.com/research/security-advisories/ghost-cve-2015-0235.txt

Trust: 4.2

url:http://www.idirect.net/partners/~/media/files/cve/idirect-posted-common-vulnerabilities-and-exposures.pdf

Trust: 2.5

url:http://www.debian.org/security/2015/dsa-3142

Trust: 2.3

url:http://packetstormsecurity.com/files/130171/exim-esmtp-ghost-denial-of-service.html

Trust: 2.3

url:http://packetstormsecurity.com/files/130768/emc-secure-remote-services-ghost-sql-injection-command-injection.html

Trust: 2.3

url:http://packetstormsecurity.com/files/130974/exim-ghost-glibc-gethostbyname-buffer-overflow.html

Trust: 2.3

url:http://packetstormsecurity.com/files/153278/wago-852-industrial-managed-switch-series-code-execution-hardcoded-credentials.html

Trust: 2.3

url:http://packetstormsecurity.com/files/164014/moxa-command-injection-cross-site-scripting-vulnerable-software.html

Trust: 2.3

url:http://packetstormsecurity.com/files/167552/nexans-ftto-gigaswitch-outdated-components-hardcoded-backdoor.html

Trust: 2.3

url:http://lists.apple.com/archives/security-announce/2015/jun/msg00002.html

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2015/sep/msg00008.html

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2015/oct/msg00005.html

Trust: 1.7

url:http://www.securityfocus.com/bid/72325

Trust: 1.7

url:http://www.securityfocus.com/bid/91787

Trust: 1.7

url:http://seclists.org/oss-sec/2015/q1/269

Trust: 1.7

url:http://seclists.org/oss-sec/2015/q1/274

Trust: 1.7

url:http://www.securityfocus.com/archive/1/534845/100/0/threaded

Trust: 1.7

url:https://seclists.org/bugtraq/2019/jun/14

Trust: 1.7

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20150128-ghost

Trust: 1.7

url:http://blogs.sophos.com/2015/01/29/sophos-products-and-the-ghost-vulnerability-affecting-linux/

Trust: 1.7

url:http://linux.oracle.com/errata/elsa-2015-0090.html

Trust: 1.7

url:http://linux.oracle.com/errata/elsa-2015-0092.html

Trust: 1.7

url:http://support.apple.com/kb/ht204942

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21695695

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21695774

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21695835

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21695860

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696131

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696243

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696526

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696600

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696602

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21696618

Trust: 1.7

url:http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

Trust: 1.7

url:http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html

Trust: 1.7

url:http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html

Trust: 1.7

url:http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html

Trust: 1.7

url:http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html

Trust: 1.7

url:http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html

Trust: 1.7

url:http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html

Trust: 1.7

url:http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html

Trust: 1.7

url:http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html

Trust: 1.7

url:http://www.websense.com/support/article/kbarticle/vulnerabilities-resolved-in-triton-apx-version-8-0

Trust: 1.7

url:https://bto.bluecoat.com/security-advisory/sa90

Trust: 1.7

url:https://cert-portal.siemens.com/productcert/pdf/ssa-994726.pdf

Trust: 1.7

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04874668

Trust: 1.7

url:https://help.ecostruxureit.com/display/public/uadco8x/struxureware+data+center+operation+software+vulnerability+fixes

Trust: 1.7

url:https://security.netapp.com/advisory/ntap-20150127-0001/

Trust: 1.7

url:https://support.apple.com/ht205267

Trust: 1.7

url:https://support.apple.com/ht205375

Trust: 1.7

url:https://www.f-secure.com/en/web/labs_global/fsc-2015-1

Trust: 1.7

url:https://www.sophos.com/en-us/support/knowledgebase/121879.aspx

Trust: 1.7

url:http://seclists.org/fulldisclosure/2015/jan/111

Trust: 1.7

url:http://seclists.org/fulldisclosure/2019/jun/18

Trust: 1.7

url:http://seclists.org/fulldisclosure/2021/sep/0

Trust: 1.7

url:http://seclists.org/fulldisclosure/2022/jun/36

Trust: 1.7

url:https://security.gentoo.org/glsa/201503-04

Trust: 1.7

url:http://www.mandriva.com/security/advisories?name=mdvsa-2015:039

Trust: 1.7

url:https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability

Trust: 1.7

url:https://www.arista.com/en/support/advisories-notices/security-advisories/1053-security-advisory-9

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2021/05/04/7

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-0126.html

Trust: 1.7

url:http://www.securitytracker.com/id/1032909

Trust: 1.7

url:http://secunia.com/advisories/62517

Trust: 1.7

url:http://secunia.com/advisories/62640

Trust: 1.7

url:http://secunia.com/advisories/62667

Trust: 1.7

url:http://secunia.com/advisories/62680

Trust: 1.7

url:http://secunia.com/advisories/62681

Trust: 1.7

url:http://secunia.com/advisories/62688

Trust: 1.7

url:http://secunia.com/advisories/62690

Trust: 1.7

url:http://secunia.com/advisories/62691

Trust: 1.7

url:http://secunia.com/advisories/62692

Trust: 1.7

url:http://secunia.com/advisories/62698

Trust: 1.7

url:http://secunia.com/advisories/62715

Trust: 1.7

url:http://secunia.com/advisories/62758

Trust: 1.7

url:http://secunia.com/advisories/62812

Trust: 1.7

url:http://secunia.com/advisories/62813

Trust: 1.7

url:http://secunia.com/advisories/62816

Trust: 1.7

url:http://secunia.com/advisories/62865

Trust: 1.7

url:http://secunia.com/advisories/62870

Trust: 1.7

url:http://secunia.com/advisories/62871

Trust: 1.7

url:http://secunia.com/advisories/62879

Trust: 1.7

url:http://secunia.com/advisories/62883

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2015/01/27/9

Trust: 1.6

url:https://security-tracker.debian.org/tracker/cve-2015-0235

Trust: 1.6

url:https://rhn.redhat.com/errata/rhsa-2015-0099.html

Trust: 1.6

url:http://lists.suse.com/pipermail/sle-security-updates/2015-january/001186.html

Trust: 1.6

url:http://www.slackware.com/security/list.php?l=slackware-security&y=2015

Trust: 1.6

url:https://wiki.ubuntu.com/securityteam/knowledgebase/ghost

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=142781412222323&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=142722450701342&w=2

Trust: 1.6

url:https://kb.juniper.net/infocenter/index?page=content&id=jsa10671

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=143145428124857&w=2

Trust: 1.6

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10100

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=142296726407499&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=142721102728110&w=2

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0235

Trust: 0.9

url:http://www.ipa.go.jp/security/announce/20150129-glibc.html

Trust: 0.8

url:http://jvn.jp/vu/jvnvu99234709/

Trust: 0.8

url:http://jvn.jp/vu/jvnvu97220341/index.html

Trust: 0.8

url:http://jvn.jp/vu/jvnvu92655282/

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0235

Trust: 0.8

url:http://www.kb.cert.org/vuls/id/967332

Trust: 0.8

url:http://www.aratana.jp/security/detail.php?id=12

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2015-0235

Trust: 0.6

url:https://cxsecurity.com/issue/wlb-2022060049

Trust: 0.6

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.2

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.2

url:http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2015-0235

Trust: 0.2

url:https://kb.juniper.net/infocenter/index?page=content&amp;id=jsa10671

Trust: 0.1

url:https://kc.mcafee.com/corporate/index?page=content&amp;id=sb10100

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=142296726407499&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=142781412222323&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=142722450701342&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=142721102728110&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=143145428124857&amp;w=2

Trust: 0.1

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_n

Trust: 0.1

url:http://www.hpe.com/support/security_bulletin_archive

Trust: 0.1

url:https://h10145.www1.hpe.com/sso/index.aspx?returnurl=..%2fdownloads%2fdow

Trust: 0.1

url:http://www.hpe.com/support/subscriber_choice

Trust: 0.1

url:https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetsea

Trust: 0.1

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2015-0101.html

Trust: 0.1

url:https://bugzilla.redhat.com/):

Trust: 0.1

url:https://access.redhat.com/security/team/key/

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#critical

Trust: 0.1

url:https://access.redhat.com/articles/11258

Trust: 0.1

url:https://access.redhat.com/security/team/contact/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3405

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-4458

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-4332

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3406

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-4458

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-4788

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-4237

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-6656

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2207

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0242

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201503-04.xml

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-4237

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4412

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3404

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-4332

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-4788

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-4424

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-0235

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-3406

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1914

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-3405

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-6656

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3480

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-2207

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-4043

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2014-4043

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0242

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-3404

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-1914

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-4412

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-3480

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4424

Trust: 0.1

url:http://slackware.com

Trust: 0.1

url:http://osuosl.org)

Trust: 0.1

url:http://slackware.com/gpg-key

Trust: 0.1

sources: CERT/CC: VU#967332 // CERT/CC: VU#967332 // VULHUB: VHN-78181 // PACKETSTORM: 134196 // PACKETSTORM: 130216 // PACKETSTORM: 131214 // PACKETSTORM: 130135 // PACKETSTORM: 130702 // PACKETSTORM: 130163 // CNNVD: CNNVD-201501-658 // JVNDB: JVNDB-2015-001251 // NVD: CVE-2015-0235

CREDITS

Qualys

Trust: 0.6

sources: CNNVD: CNNVD-201501-658

SOURCES

db:CERT/CCid:VU#967332
db:CERT/CCid:VU#967332
db:VULHUBid:VHN-78181
db:PACKETSTORMid:134196
db:PACKETSTORMid:130216
db:PACKETSTORMid:131214
db:PACKETSTORMid:130135
db:PACKETSTORMid:130702
db:PACKETSTORMid:130163
db:CNNVDid:CNNVD-201501-658
db:JVNDBid:JVNDB-2015-001251
db:NVDid:CVE-2015-0235

LAST UPDATE DATE

2025-09-27T23:43:54.363000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#967332date:2015-10-22T00:00:00
db:CERT/CCid:VU#967332date:2015-10-22T00:00:00
db:VULHUBid:VHN-78181date:2021-11-17T00:00:00
db:CNNVDid:CNNVD-201501-658date:2022-06-21T00:00:00
db:JVNDBid:JVNDB-2015-001251date:2016-11-22T00:00:00
db:NVDid:CVE-2015-0235date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CERT/CCid:VU#967332date:2015-01-28T00:00:00
db:CERT/CCid:VU#967332date:2015-01-28T00:00:00
db:VULHUBid:VHN-78181date:2015-01-28T00:00:00
db:PACKETSTORMid:134196date:2015-11-03T16:53:42
db:PACKETSTORMid:130216date:2015-02-03T16:49:41
db:PACKETSTORMid:131214date:2015-03-31T15:57:26
db:PACKETSTORMid:130135date:2015-01-29T06:05:51
db:PACKETSTORMid:130702date:2015-03-09T20:15:21
db:PACKETSTORMid:130163date:2015-01-29T18:21:00
db:CNNVDid:CNNVD-201501-658date:2015-01-28T00:00:00
db:JVNDBid:JVNDB-2015-001251date:2015-01-29T00:00:00
db:NVDid:CVE-2015-0235date:2015-01-28T19:59:00.063