CVE-2015-5180
Publication date 10 August 2015
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
From the Ubuntu Security Team
Florian Weimer discovered a NULL pointer dereference in the DNS resolver of the GNU C Library. An attacker could use this to cause a denial of service.
Status
Package | Ubuntu Release | Status |
---|---|---|
eglibc | 20.04 LTS focal | Not in release |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Ignored | |
glibc | 20.04 LTS focal |
Not affected
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial | Ignored | |
14.04 LTS trusty | Not in release | |
Notes
tyhicks
See test case in the bug no fix upstream as of 2016-09-09
sbeattie
patch committed upstream on 2016-12-31; renames symbol so backporting may not be easy. commit included in glibc 2.25 release debian fixed this in unstable in 2.24-9 fixing this does indeed break the internal ABI between libnss_dns and libresolv. We're backing out this change. reverted from zesty in 2.24-9ubuntu2 by infinity. For existing releases, DO NOT APPLY THIS PATCH due to ABI breakage. Fix will come in to 17.10 when we get glibc-2.25 as we do not guarantee ABI for libresolv internals across different glibc releases, just for upgrades for same versions e.g. (2.24 -> 2.24) REPEAT: DO NOT APPLY THIS PATCH (UNMODIFIED) IN A STABLE RELEASE
mdeslaur
marking this issue as ignored, as we will not be fixing this in Ubuntu stable releases.
Patch details
Package | Patch details |
---|---|
glibc |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-3239-1
- GNU C Library vulnerabilities
- 21 March 2017