ESXi 5.5 < Build 3568722 / 6.0 < Build 3568940 glibc DNS Resolver RCE (VMSA-2016-0002) (remote check)

Critical Nessus Plugin ID 88906

Synopsis

The remote VMware ESXi host is affected by a remote code execution vulnerability.

Description

The remote VMware ESXi host is 5.5 prior to build 3568722 or 6.0 prior to build 3568940. It is, therefore, affected by a stack-based buffer overflow condition in the GNU C Library (glibc) DNS client-side resolver due to improper validation of user-supplied input when looking up names via the getaddrinfo() function. An attacker can exploit this to execute arbitrary code by using an attacker-controlled domain name, an attacker-controlled DNS server, or through a man-in-the-middle attack.

Solution

Apply the appropriate patch as referenced in the vendor advisory.

See Also

http://www.vmware.com/security/advisories/VMSA-2016-0002.html

http://kb.vmware.com/kb/2144353

http://kb.vmware.com/kb/2144357

http://kb.vmware.com/kb/2144057

http://kb.vmware.com/kb/2144054

http://www.nessus.org/u?8bdae0a0

https://sourceware.org/bugzilla/show_bug.cgi?id=18665

Plugin Details

Severity: Critical

ID: 88906

File Name: vmware_VMSA-2016-0002_remote.nasl

Version: 1.12

Type: remote

Family: Misc.

Published: 2016/02/23

Updated: 2018/08/06

Dependencies: 57396

Risk Information

Risk Factor: Critical

CVSS v2.0

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:vmware:esxi

Required KB Items: Host/VMware/version, Host/VMware/release

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2016/02/21

Vulnerability Publication Date: 2015/07/14

Reference Information

CVE: CVE-2015-7547

BID: 83265

VMSA: 2016-0002

IAVB: 2016-B-0036, 2016-B-0037

CERT: 457759

EDB-ID: 39454