Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

GNU glibc gethostbyname Function Buffer Overflow Vulnerability

cisco-sa-20150128-ghost · Critical · Published · Updated

On January 27, 2015, a buffer overflow vulnerability in the GNU C library (glibc) was publicly announced. This vulnerability is related to the various gethostbyname functions included in glibc and affects applications that call these functions. This vulnerability may allow an attacker to obtain sensitive information from an exploited system or, in some instances, perform remote code execution with the privileges of the application being exploited. The glibc library is a commonly used third-party software component that is released by the GNU software project and a number of Cisco products are likely affected. This advisory will be updated as additional information becomes available. Cisco will release free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150128-ghost

Cisco advisory · CSAF JSON

Workarounds

There are currently no network-based mitigations for this vulnerability or any mitigations that can be performed directly on affected systems.

Cisco has published an Event Response for this vulnerability: http://www.cisco.com/web/about/security/intelligence/ERP_GHOST_29-Jan-2015.html ["http://www.cisco.com/web/about/security/intelligence/ERP_GHOST_29-Jan-2015.html"]

CVEsCVE-2015-0235
Cisco Bug IDsCSCus66766, CSCus68529, CSCus68533, CSCus68534, CSCus68537, CSCus68770, CSCus68905, CSCus68928, CSCus69387, CSCus69388, CSCus69422, CSCus69424, CSCus69430, CSCus69431, CSCus69460, CSCus69463, CSCus69472, CSCus69475, CSCus69491, CSCus69493, CSCus69494, CSCus69495, CSCus69513, CSCus69517, CSCus69523, CSCus69524, CSCus69525, CSCus69529, CSCus69535, CSCus69539, CSCus69543, CSCus69547, CSCus69550, CSCus69558, CSCus69559, CSCus69563, CSCus69570, CSCus69585, CSCus69592, CSCus69606, CSCus69607, CSCus69609, CSCus69610, CSCus69612, CSCus69615, CSCus69617, CSCus69620, CSCus69622, CSCus69646, CSCus69665, CSCus69682, CSCus69696, CSCus69731, CSCus69732, CSCus69738, CSCus69763, CSCus69766, CSCus69768, CSCus69769, CSCus69787, CSCus69788, CSCus69789, CSCus69791, CSCus69792, CSCus69809, CSCus70263, CSCus71708, CSCus71883, CSCus74488, CSCus85675, CSCus85759, CSCus95601
CVSS ScoreBase NA
Product Names From Source
Cisco Application and Content Networking System (ACNS) Software, Cisco Unity, CiscoWorks LAN Management Solution (LMS) for Windows, CiscoWorks LAN Management Solution (LMS) for Solaris, Cisco Emergency Responder, Cisco Unified Contact Center, Cisco IOS XR Software, Cisco Intrusion Prevention System (IPS), Cisco Wireless Location Appliance, Cisco Wide Area Application Services (WAAS), Cisco Wireless LAN Controller (WLC), CiscoWorks LAN Management Solution (LMS), Cisco IP Interoperability and Collaboration System (IPICS), Cisco Service Control Engine (SCE), Cisco Unity Connection, Cisco TelePresence, Cisco Physical Access Gateway, Cisco Unified Contact Center Express, Cisco IOS XE Software, Cisco Video Surveillance Media Server Software, Cisco Digital Media Manager Software, Cisco ACE GSS 4400 Series Global Site Selector (GSS) devices, Cisco MeetingPlace Server, Cisco Network Analysis Module (NAM) Software, Cisco WebEx Meeting Center, Cisco WebEx PCNow, Cisco Show and Share, Cisco Mobility Services Engine, Cisco TelePresence Video Communication Server (VCS), Cisco TelePresence Recording Server, Cisco TelePresence Multipoint Switch, Cisco ASA CX Context-Aware Security Software, Cisco Prime Security Manager (PRSM), Cisco Prime Data Center Network Manager (DCNM), Cisco Prime LAN Management Solution (LMS), Cisco Content Security Management Appliance (SMA), Cisco Prime Infrastructure, Cisco WebEx Meetings Server, Cisco WebEx Node for MCS, Cisco Unified Computing System Central Software, Cisco Enterprise Content Delivery System (ECDS), Cisco Virtualization Experience Media Engine, Cisco ASR 5000 Series Software, Cisco Finesse, Cisco SocialMiner, Cisco MediaSense, Cisco Video Surveillance 4000 Series IP Camera, Cisco Unified SIP Proxy, Cisco Prime Network Registrar, Cisco Videoscape Distribution Suite Transparent Caching (VDS TC), Cisco Digital Content Manager (DCM) Software, Cisco Unified Intelligence Center, Cisco Prime Service Catalog, Cisco Nexus 1000V Switch, Cisco Expressway, Cisco Jabber Guest, Cisco Visual Quality Experience, Cisco Small Business ISA500 Series Integrated Security Appliance Software, Cisco Prime License Manager, Cisco Prime Collaboration Deployment, Cisco TelePresence MPS Series, Cisco Prime IP Express, Cisco onePK All-in-One Virtual Machine, Cisco Telepresence Conductor, Cisco Videoscape Conductor, Cisco Prime Network, Cisco Agent Desktop, Cisco Paging Server, Cisco SPA112 2-Port Phone Adapter, Cisco SPA122 ATA with Router, Cisco SPA232D Multi-Line DECT ATA, Cisco Unified 7800 Series IP Phones, Cisco D9036 Modular Encoding Platform, Cisco Nexus 3000 Series Switch, Cisco Hosted Collaboration Mediation Fulfillment, Cisco Intercloud Fabric, Cisco Registered Envelope Service, Cisco Secure Email and Web Manager, Intrusion Prevention System (IPS)

Related Products

Product CVE Evidence
Intrusion Prevention System (IPS) CVE-2015-0235 Cisco OpenVuln
CiscoWorks LAN Management Solution (LMS) for Windows CVE-2015-0235 Cisco OpenVuln
CiscoWorks LAN Management Solution (LMS) for Solaris CVE-2015-0235 Cisco OpenVuln
CiscoWorks LAN Management Solution (LMS) CVE-2015-0235 Cisco OpenVuln
Cisco onePK All-in-One Virtual Machine CVE-2015-0235 Cisco OpenVuln
Cisco Wireless Location Appliance CVE-2015-0235 Cisco OpenVuln
Cisco Wireless LAN Controller (WLC) CVE-2015-0235 Cisco OpenVuln
Cisco Wide Area Application Services (WAAS) CVE-2015-0235 Cisco OpenVuln
Cisco Webex Meetings CVE-2015-0235 Cisco OpenVuln
Cisco WebEx PCNow CVE-2015-0235 Cisco OpenVuln
Cisco WebEx Node for MCS CVE-2015-0235 Cisco OpenVuln
Cisco WebEx Meetings Server CVE-2015-0235 Cisco OpenVuln
Cisco WebEx Meeting Center CVE-2015-0235 Cisco OpenVuln
Cisco Visual Quality Experience CVE-2015-0235 Cisco OpenVuln
Cisco Virtualization Experience Media Engine CVE-2015-0235 Cisco OpenVuln
Cisco Videoscape Distribution Suite Transparent Caching (VDS TC) CVE-2015-0235 Cisco OpenVuln
Cisco Videoscape Conductor CVE-2015-0235 Cisco OpenVuln
Cisco Video Surveillance Media Server Software CVE-2015-0235 Cisco OpenVuln
Cisco Video Surveillance 4000 Series IP Camera CVE-2015-0235 Cisco OpenVuln
Cisco Unity Connection CVE-2015-0235 Cisco OpenVuln
Cisco Unity CVE-2015-0235 Cisco OpenVuln
Cisco Unified SIP Proxy CVE-2015-0235 Cisco OpenVuln
Cisco Unified Intelligence Center CVE-2015-0235 Cisco OpenVuln
Cisco Unified Contact Center Express CVE-2015-0235 Cisco OpenVuln
Cisco Unified Contact Center CVE-2015-0235 Cisco OpenVuln
Cisco Unified Computing System Central Software CVE-2015-0235 Cisco OpenVuln
Cisco Unified 7800 Series IP Phones CVE-2015-0235 Cisco OpenVuln
Cisco Telepresence Conductor CVE-2015-0235 Cisco OpenVuln
Cisco TelePresence Video Communication Server (VCS) CVE-2015-0235 Cisco OpenVuln
Cisco TelePresence Recording Server CVE-2015-0235 Cisco OpenVuln
Cisco TelePresence Multipoint Switch CVE-2015-0235 Cisco OpenVuln
Cisco TelePresence MPS Series CVE-2015-0235 Cisco OpenVuln
Cisco TelePresence CVE-2015-0235 Cisco OpenVuln
Cisco SocialMiner CVE-2015-0235 Cisco OpenVuln
Cisco Small Business ISA500 Series Integrated Security Appliance Software CVE-2015-0235 Cisco OpenVuln
Cisco Show and Share CVE-2015-0235 Cisco OpenVuln
Cisco Service Control Engine (SCE) CVE-2015-0235 Cisco OpenVuln
Cisco Secure Email and Web Manager CVE-2015-0235 Cisco OpenVuln
Cisco Secure Email CVE-2015-0235 Cisco OpenVuln
Cisco SPA232D Multi-Line DECT ATA CVE-2015-0235 Cisco OpenVuln
Cisco SPA122 ATA with Router CVE-2015-0235 Cisco OpenVuln
Cisco SPA112 2-Port Phone Adapter CVE-2015-0235 Cisco OpenVuln
Cisco Registered Envelope Service CVE-2015-0235 Cisco OpenVuln
Cisco Prime Service Catalog CVE-2015-0235 Cisco OpenVuln
Cisco Prime Security Manager (PRSM) CVE-2015-0235 Cisco OpenVuln
Cisco Prime Network Registrar CVE-2015-0235 Cisco OpenVuln
Cisco Prime Network CVE-2015-0235 Cisco OpenVuln
Cisco Prime License Manager CVE-2015-0235 Cisco OpenVuln
Cisco Prime LAN Management Solution (LMS) CVE-2015-0235 Cisco OpenVuln
Cisco Prime Infrastructure CVE-2015-0235 Cisco OpenVuln
Cisco Prime IP Express CVE-2015-0235 Cisco OpenVuln
Cisco Prime Data Center Network Manager (DCNM) CVE-2015-0235 Cisco OpenVuln
Cisco Prime Collaboration Deployment CVE-2015-0235 Cisco OpenVuln
Cisco Prime Collaboration CVE-2015-0235 Cisco OpenVuln
Cisco Physical Access Gateway CVE-2015-0235 Cisco OpenVuln
Cisco Paging Server CVE-2015-0235 Cisco OpenVuln
Cisco Nexus 3000 Series Switch CVE-2015-0235 Cisco OpenVuln
Cisco Nexus 1000V Switch CVE-2015-0235 Cisco OpenVuln
Cisco Network Analysis Module (NAM) Software CVE-2015-0235 Cisco OpenVuln
Cisco Mobility Services Engine CVE-2015-0235 Cisco OpenVuln
Cisco MeetingPlace Server CVE-2015-0235 Cisco OpenVuln
Cisco MediaSense CVE-2015-0235 Cisco OpenVuln
Cisco Jabber Guest CVE-2015-0235 Cisco OpenVuln
Cisco Jabber CVE-2015-0235 Cisco OpenVuln
Cisco Intrusion Prevention System (IPS) CVE-2015-0235 Cisco OpenVuln
Cisco Intercloud Fabric CVE-2015-0235 Cisco OpenVuln
Cisco IP Interoperability and Collaboration System (IPICS) CVE-2015-0235 Cisco OpenVuln
Cisco IOS XR Software CVE-2015-0235 Cisco OpenVuln
Cisco IOS XE Software CVE-2015-0235 Cisco OpenVuln
Cisco IOS CVE-2015-0235 Cisco OpenVuln
Cisco Hosted Collaboration Mediation Fulfillment CVE-2015-0235 Cisco OpenVuln
Cisco Finesse CVE-2015-0235 Cisco OpenVuln
Cisco Expressway CVE-2015-0235 Cisco OpenVuln
Cisco Enterprise Content Delivery System (ECDS) CVE-2015-0235 Cisco OpenVuln
Cisco Emergency Responder CVE-2015-0235 Cisco OpenVuln
Cisco Digital Media Manager Software CVE-2015-0235 Cisco OpenVuln
Cisco Digital Content Manager (DCM) Software CVE-2015-0235 Cisco OpenVuln
Cisco D9036 Modular Encoding Platform CVE-2015-0235 Cisco OpenVuln
Cisco Content Security Management Appliance (SMA) CVE-2015-0235 Cisco OpenVuln
Cisco Application and Content Networking System (ACNS) Software CVE-2015-0235 Cisco OpenVuln
Cisco Agent Desktop CVE-2015-0235 Cisco OpenVuln
Cisco ASR 5000 Series Software CVE-2015-0235 Cisco OpenVuln
Cisco ASA CX Context-Aware Security Software CVE-2015-0235 Cisco OpenVuln
Cisco ACE GSS 4400 Series Global Site Selector (GSS) devices CVE-2015-0235 Cisco OpenVuln
Application and Content Networking System (ACNS) Software CVE-2015-0235 Cisco OpenVuln
Cisco Catalyst 9600 Series Switches CVE-2015-0235 Cisco OpenVuln · software-dependent
Cisco Catalyst 9500 Series Switches CVE-2015-0235 Cisco OpenVuln · software-dependent
Cisco Catalyst 9400 Series Switches CVE-2015-0235 Cisco OpenVuln · software-dependent
Cisco Catalyst 9300 Series Switches CVE-2015-0235 Cisco OpenVuln · software-dependent
Cisco Catalyst 9200 Series Switches CVE-2015-0235 Cisco OpenVuln · software-dependent