CVE-2015-0235
eglibc - security update
EPSS 94.9%
描述
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
如何修補 CVE-2015-0235
要修補 CVE-2015-0235,請將受影響套件升級到下列已修補版本。
- Debian/eglibc—升級至 2.11.3-4+deb6u4 或更新版本
- Debian/glibc—升級至 2.18-1 或更新版本
CVE-2015-0235 正在被利用嗎?
可能 — EPSS 為 94.9%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- from 0, < 2.11.3-4+deb6u4
- from 0, < 2.18-1