CVE-2015-5277

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.

References

http://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html

http://rhn.redhat.com/errata/RHSA-2015-2172.html

http://seclists.org/fulldisclosure/2019/Sep/7

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html

http://www.securityfocus.com/bid/78092

http://www.securitytracker.com/id/1034196

http://www.ubuntu.com/usn/USN-2985-1

http://www.ubuntu.com/usn/USN-2985-2

https://bugzilla.redhat.com/show_bug.cgi?id=1262914

https://seclists.org/bugtraq/2019/Sep/7

https://security.gentoo.org/glsa/201702-11

https://sourceware.org/bugzilla/show_bug.cgi?id=17079

https://sourceware.org/ml/libc-alpha/2014-09/msg00088.html

Details

Source: MITRE

Published: 2015-12-17

Updated: 2017-07-01

Type: CWE-119

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (10 total)

IDNameProductFamilySeverity
125005EulerOS Virtualization 3.0.1.0 : glibc (EulerOS-SA-2019-1552)NessusHuawei Local Security Checks
critical
97254GLSA-201702-11 : GNU C Library: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
91341Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : eglibc, glibc regression (USN-2985-2)NessusUbuntu Local Security Checks
critical
91334Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : eglibc, glibc vulnerabilities (USN-2985-1)NessusUbuntu Local Security Checks
critical
88573RHEL 7 : glibc (RHSA-2015:2589)NessusRed Hat Local Security Checks
high
87638Scientific Linux Security Update : glibc on SL7.x x86_64_important (20151119)NessusScientific Linux Local Security Checks
high
87343Amazon Linux AMI : glibc (ALAS-2015-617)NessusAmazon Linux Local Security Checks
high
87139CentOS 7 : glibc (CESA-2015:2172)NessusCentOS Local Security Checks
high
87091Oracle Linux 7 : glibc (ELSA-2015-2172)NessusOracle Linux Local Security Checks
high
86974RHEL 7 : glibc (RHSA-2015:2172)NessusRed Hat Local Security Checks
high