Vulnerability Name:

CVE-2015-7510 (CCN-132654)

Assigned:2015-11-23
Published:2015-11-23
Updated:2022-01-28
Summary:Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2015-7510

Source: CCN
Type: Red Hat Bugzilla – Bug 1284642
(CVE-2015-7510) CVE-2015-7510 systemd: Stack overflow in nss-mymachines

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory, VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1284642

Source: XF
Type: UNKNOWN
systemd-cve20157510-bo(132654)

Source: CCN
Type: systemd GIT Repository
nss-mymachines: do not allow overlong machine names

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/keszybz/systemd/commit/cb31827d62066a04b02111df3052949fda4b6888

Source: CCN
Type: systemd GIT Repository
Stack overflows in nss_mymachines (CVE-2015-7510) #2002

Source: CONFIRM
Type: Exploit, Patch, Third Party Advisory
https://github.com/systemd/systemd/issues/2002

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-7510

Vulnerable Configuration:Configuration 1:
  • cpe:/a:systemd_project:systemd:223:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:systemd_project:systemd:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20157510
    V
    CVE-2015-7510
    2023-06-22
    oval:org.opensuse.security:def:7678
    P
    libsystemd0-249.16-150400.8.25.7 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:800
    P
    Security update for libjpeg-turbo (Moderate)
    2022-10-04
    oval:org.opensuse.security:def:3086
    P
    gnome-shell-search-provider-nautilus-3.20.3-23.12.10 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94716
    P
    libsystemd0-249.11-150400.6.8 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:317
    P
    systemd-bash-completion-234-24.82.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:201
    P
    libsoup-2_4-1-2.68.3-2.32 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:206
    P
    libsystemd0-246.13-5.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:490
    P
    Security update for MozillaFirefox (Important)
    2022-05-19
    oval:org.opensuse.security:def:112863
    P
    libsystemd0-228-17.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:1135
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:106324
    P
    libsystemd0-228-17.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:96699
    P
    libsystemd0-234-24.25.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61579
    P
    libsystemd0-234-24.25.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89734
    P
    libsystemd0-234-24.25.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103389
    P
    libsystemd0-234-24.25.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71320
    P
    libsystemd0-234-24.25.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:49187
    P
    Security update for compat-openssl098 (Important)
    2021-08-27
    oval:org.opensuse.security:def:47712
    P
    libgoa-1_0-0-3.20.5-9.6 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47051
    P
    libmusicbrainz4-2.1.5-27.79 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47011
    P
    libcgroup-tools-0.41.rc1-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47950
    P
    apache2-mod_apparmor-2.8.2-51.18.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48010
    P
    ft2demos-2.6.3-7.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47275
    P
    grub2-2.02-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47026
    P
    libgypsy0-0.9-6.22 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48137
    P
    libkde4-32bit-4.12.0-10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47637
    P
    guestfs-data-1.32.4-21.3.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47340
    P
    libecpg6-9.6.3-2.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48239
    P
    mariadb-10.2.25-3.19.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47783
    P
    libsndfile1-1.0.25-36.16.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47564
    P
    axis-1.4-290.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47879
    P
    rsync-3.1.0-13.13.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47926
    P
    xorg-x11-7.6_1-14.17 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47183
    P
    xfsprogs-4.3.0-8.8 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47012
    P
    libdcerpc-atsvc0-4.2.4-26.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48072
    P
    libXRes1-1.0.7-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47423
    P
    libupsclient1-2.7.1-4.55 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47147
    P
    rsync-3.1.0-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48168
    P
    libpcap1-1.8.1-10.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47721
    P
    libimobiledevice6-1.2.0-7.31 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47472
    P
    policycoreutils-2.5-9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47848
    P
    perl-Archive-Zip-1.34-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:62335
    P
    systemd-bash-completion-234-24.82.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1246
    P
    systemd-bash-completion-234-24.82.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71965
    P
    libsystemd0-246.13-5.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101093
    P
    systemd-bash-completion-234-24.82.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72076
    P
    systemd-bash-completion-234-24.82.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62224
    P
    libsystemd0-246.13-5.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:69892
    P
    Security update for sqlite3 (Important)
    2021-07-14
    oval:org.opensuse.security:def:48642
    P
    vorbis-tools-1.4.0-26.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61290
    P
    libsystemd0-234-22.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48931
    P
    libmwaw-0_3-3-0.3.13-7.9.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46723
    P
    libexif12-0.6.21-6.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46858
    P
    tigervnc-1.4.3-7.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71090
    P
    python2-urllib3-1.22-4.26 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48588
    P
    pam-1.1.8-14.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70977
    P
    libical2-2.0.0-1.37 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71031
    P
    libsystemd0-234-22.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46722
    P
    libevent-2_0-5-2.0.21-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48877
    P
    libwmf-0_2-7-0.2.8.4-242.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46737
    P
    libjavascriptcoregtk-3_0-0-2.4.8-16.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:69787
    P
    Security update for salt (Critical)
    2021-02-26
    oval:org.opensuse.security:def:116793
    P
    libsystemd0-234-24.49.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71630
    P
    libsystemd0-234-24.49.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100569
    P
    libsystemd0-234-24.49.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61889
    P
    libsystemd0-234-24.49.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:93856
    P
    libsystemd0-234-24.49.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107235
    P
    libsystemd0-234-24.49.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:66536
    P
    libsystemd0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64303
    P
    libXfont2-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67737
    P
    libsystemd0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49241
    P
    libsystemd0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66444
    P
    libXrandr-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73227
    P
    libsystemd0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64390
    P
    libsystemd0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67637
    P
    less on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73109
    P
    java-11-openjdk on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.trusty:def:20157510000
    V
    CVE-2015-7510 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-09-25
    oval:com.ubuntu.xenial:def:20157510000
    V
    CVE-2015-7510 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-09-25
    oval:com.ubuntu.xenial:def:201575100000000
    V
    CVE-2015-7510 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-09-25
    BACK
    systemd_project systemd 223
    systemd_project systemd *