logo

GHOST Vulnerability (CVE‑2015‑0235)

ID: 72316a5b-6326-523b-b6c4-7e0d7c0ca92e

STIX ID: report--72316a5b-6326-523b-b6c4-7e0d7c0ca92e

Feed Name: NCC Research

Threat Score
85/100

Date Published: 2026-05-15

Date Updated: 2026-07-30

...
...

This advisory documents GHOST (CVE-2015-0235), a severe heap-based buffer overflow in glibc's hostname handling (gethostbyname/gethostbyname2) present in glibc 2.2–2.17 that allows unauthenticated remote code execution when processing long numeric/dotted hostnames; it lists affected distributions and packages, notes an Exim exploit and imminent PoC, and provides detection and remediation steps (update to glibc ≥2.18, patch distributions, and restart affected processes/binaries).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.