ESXi 5.5 < Build 3568722 / 6.0 < Build 3568940 glibc DNS Resolver RCE (VMSA-2016-0002) (remote check)

high Nessus Plugin ID 88906


The remote VMware ESXi host is affected by a remote code execution vulnerability.


The remote VMware ESXi host is 5.5 prior to build 3568722 or 6.0 prior to build 3568940. It is, therefore, affected by a stack-based buffer overflow condition in the GNU C Library (glibc) DNS client-side resolver due to improper validation of user-supplied input when looking up names via the getaddrinfo() function. An attacker can exploit this to execute arbitrary code by using an attacker-controlled domain name, an attacker-controlled DNS server, or through a man-in-the-middle attack.


Apply the appropriate patch as referenced in the vendor advisory.

See Also

Plugin Details

Severity: High

ID: 88906

File Name: vmware_VMSA-2016-0002_remote.nasl

Version: 1.16

Type: remote

Family: Misc.

Published: 2/23/2016

Updated: 1/6/2021

Risk Information


Risk Factor: High

Score: 8.4


Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: E:POC/RL:OF/RC:C

CVSS Score Source: CVE-2015-7547


Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:vmware:esxi

Required KB Items: Host/VMware/version, Host/VMware/release

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/21/2016

Vulnerability Publication Date: 7/14/2015

Reference Information

CVE: CVE-2015-7547

BID: 83265

VMSA: 2016-0002

CERT: 457759

EDB-ID: 39454