CVE-2015-5180: Null Pointer Dereference
It was discovered that the glibc DNS resolver dereferenced a NULL pointer when processing a specific, but valid resource record type.
Acknowledgements:
Name: Florian Weimer (Red Hat Product Security)
Other sources
resquery in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5180?
CVE-2015-5180 is classified as a medium severity vulnerability.
How do I fix CVE-2015-5180?
To fix CVE-2015-5180, update glibc to versions above 2.24, specifically to 2.31-13+deb11u10 or later.
What conditions can lead to exploitation of CVE-2015-5180?
CVE-2015-5180 can be exploited by remote attackers through specially crafted DNS responses.
Which systems are affected by CVE-2015-5180?
CVE-2015-5180 affects Ubuntu Linux versions 12.04, 14.04, 16.04 and GNU C Library (glibc) versions up to 2.24.
What components are involved in CVE-2015-5180?
CVE-2015-5180 involves the res_query function in the libresolv library of glibc.