CVE-2015-0235: Apple Mac OS X

High severity, CVSS 10.0. EPSS: 94.6% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

Affected products

  • Apple Mac OS X: before 10.11.1 (fixed in 10.11.1)
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • GNU Glibc: from 2.0, before 2.18 (fixed in 2.18)
  • IBM Pureapplication System: version 1.0.0.0 only; version 1.1.0.0 only; version 2.0.0.0 only
  • IBM Security Access Manager For Enterprise Single Sign-On: version 8.2 only
  • Oracle Communications Application Session Controller: before 3.7.1 (fixed in 3.7.1)
  • Oracle Communications Eagle Application Processor: version 16.0 only
  • Oracle Communications Eagle Lnp Application Processor: version 10.0 only
  • Oracle Communications Lsms: version 13.1 only
  • Oracle Communications Policy Management: version 9.7.3 only; version 9.9.1 only; version 10.4.1 only; version 11.5 only; version 12.1.1 only
  • Oracle Communications Session Border Controller: before 7.2.0 (fixed in 7.2.0); version 7.2.0 only; version 8.0.0 only
  • Oracle Communications User Data Repository: from 10.0.0, up to and including 10.0.1
  • Oracle Communications WebRTC Session Controller: version 7.0 only; version 7.1 only; version 7.2 only
  • Oracle Exalogic Infrastructure: version 1.0 only; version 2.0 only
  • Oracle Linux: version 5 only; version 7 only
  • Oracle Vm VirtualBox: before 5.1.24 (fixed in 5.1.24)
  • PHP PHP: from 5.4.0, before 5.4.38 (fixed in 5.4.38); from 5.5.0, before 5.5.22 (fixed in 5.5.22); from 5.6.0, before 5.6.6 (fixed in 5.6.6)
  • Red Hat Virtualization: version 6.0 only

Published 2015-01-28. Last modified 2026-06-17.