CVE-2015-7547
Description
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
In plain language
AI Worth attentionCVE-2015-7547 is a glibc (libc6) security bug (in versions older than 2.23) that lets attackers send a specially crafted DNS reply to crash services or, more rarely, potentially run malicious code—if your server uses DNS lookups over the network with IPv6-capable settings. Most small businesses should act if this machine is internet-facing or performs network DNS resolution.
CVE-2015-7547 is a set of stack-based buffer overflows in glibc’s libresolv functions (send_dg/send_vc) in libc6 before 2.23, triggered by a specially crafted DNS response during getaddrinfo resolution for IPv6/dual-stack DNS behavior; it can be reached over the network with no authentication or user interaction.
What to do now
- Check the glibc/libc6 version on each affected machine (you need libc6/glibc older than 2.23 to be at risk).
- Verify whether the machine performs DNS lookups in normal operation (especially IPv6/dual-stack address resolution) and whether it can receive network traffic from untrusted sources.
- Upgrade glibc/libc6 to version 2.23 or higher on all hosts that run the vulnerable glibc.
- Re-test: restart services that use name resolution and confirm normal operation after the upgrade.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-7547 and every CVE in our database. Create a free account — no credit card required.
Create Free Account