On Feb 16th, Google published CVE-2015-7547: glibc getaddrinfo vulnerability that affects all SW compiled with GLIBC for many versions. As this vulnerability is in the code used to parse network addresses it is possible, in theory, to remotely exploit it.
The Google team published a crashing POC but chose not to disclose an exploit. Our team has been studying the vulnerability and developed a technique to exploit this vulnerability and achieve remote code execution. The technique applies to many different SW products that are compiled using the old version.
=======
Gal De Leon is a security researcher at Palo Alto Networks. He has a variety of skills, ranging from web development, C++, exploitation and reverse engineering. Gal develops exploit mitigations for Palo Alto Networks Traps advanced endpoint protection solution.
------
Nadav Markus is a security researcher at Palo Alto Networks. He develops unique exploit mitigations for Palo Alto Networks Traps advanced endpoint protection solution. Nadav is a python enthusiast, and also enjoys reverse-engineering, exploitation and researching software-security in general.