logo

Ghost Vulnerability Replays Third Party Code Woes

ID: 2664a63d-59bb-52e2-872a-533c36fa095c

STIX ID: report--2664a63d-59bb-52e2-872a-533c36fa095c

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2015-01-28

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

A remotely exploitable buffer overflow in glibc's legacy gethostbyname() functions (dubbed 'Ghost') was disclosed by Qualys; a proof-of-concept remote exploit was created (against Exim), the flaw affected many Unix/Linux distributions, and although a fix landed in glibc-2.18 (May 2013) it was inadvertent leaving numerous systems exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.