Article ID: 124310, created on Jan 28, 2015, last review on Jun 17, 2016

  • Applies to:
  • Operations Automation
  • Plesk for Linux/Unix
  • Virtuozzo
  • Virtuozzo containers for Linux
  • Virtuozzo containers for Windows 6.0
  • Virtuozzo hypervisor
  • Virtual Automation
  • H-Sphere


During a code audit performed internally at Qualys a heap-based buffer overflow was found in glibc's "__nss_hostname_digits_dots()" function, which is used by the gethostbyname() and gethostbyname2() glibc function calls.


There is a remote code execution risk due to this vulnerability. An attacker who exploits this issue can gain complete control of the compromised system.

More information about CVE-2015-0235 can be found in Qualys Blog and on Openwall website.


To close the vulnerability, install the latest available version of glibc from the OS vendor repository.

Call to Action

Install security patch following the instructions provided in these Parallels Knowledge base articles:

The fixed version of glibc have been released by the OS vendors:

Parallels takes the security of our customers very seriously and encourages you to take the recommended actions as soon as possible.

We also strongly encourage you to stay connected to Parallels for important product-related information via these methods:

Search Words


ghost glibc

Security Advisory


a26b38f94253cdfbf1028d72cf3a498b 2897d76d56d2010f4e3a28f864d69223 d02f9caf3e11b191a38179103495106f e8e50b42231236b82df27684e7ec0beb e0aff7830fa22f92062ee4db78133079 caea8340e2d186a540518d08602aa065 319940068c5fa20655215d590b7be29b 0dd5b9380c7d4884d77587f3eb0fa8ef 198398b282069eaf2d94a6af87dcb3ff 614fd0b754f34d5efe9627f2057b8642 400e18f6ede9f8be5575a475d2d6b0a6 29d1e90fd304f01e6420fbe60f66f838 56797cefb1efc9130f7c48a7d1db0f0c a914db3fdc7a53ddcfd1b2db8f5a1b9c f213b9fa8759d57bee5d547445806fe7 6311ae17c1ee52b36e68aaf4ad066387 5356b422f65bdad1c3e9edca5d74a1ae 6f8e3eda12803cf88a9587e9782c9ed6 965b49118115a610e93635d21c5694a8

Email subscription for changes to this article
Save as PDF