---
cve: "CVE-2015-0235"
severity: "LOW"
cvss: 3.1
epss: "94.9%"
vendor: "n/a"
kev: false
exploited: false
published: "2015-01-28 19:59:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T15:21:48+02:00"
---

# CVE-2015-0235

> 3.1 LOW · 🧪 PoC

## Beschreibung

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

## Exploit-Evidenz

- [EDB-36421 — Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)](https://www.exploit-db.com/exploits/36421) ✅
- [EDB-35951 — Exim ESMTP 4.80 - glibc gethostbyname Denial of Service](https://www.exploit-db.com/exploits/35951)

## Referenzen

- <http://www.securityfocus.com/bid/72325>
- <http://marc.info/?l=bugtraq&m=142296726407499&w=2>
- <http://www-01.ibm.com/support/docview.wss?uid=swg21696131>
- <http://secunia.com/advisories/62883>
- <http://secunia.com/advisories/62691>
- <http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html>
- <http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html>
- <http://packetstormsecurity.com/files/130974/Exim-GHOST-glibc-gethostbyname-Buffer-Overflow.html>
- <https://support.apple.com/HT205375>
- <http://marc.info/?l=bugtraq&m=142722450701342&w=2>
- <http://seclists.org/oss-sec/2015/q1/269>
- <http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0>
- <http://secunia.com/advisories/62698>
- <http://secunia.com/advisories/62640>
- <http://www.securitytracker.com/id/1032909>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2015-0235) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
