Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5180

Опубликовано: 03 окт. 2016
Источник: debian
EPSS Средний

Описание

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
c-aresfixed1.12.0-1package

Примечания

  • https://c-ares.haxx.se/adv_20160929.html

  • https://c-ares.haxx.se/CVE-2016-5180.patch

EPSS

Процентиль: 96%
0.22414
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

CVSS3: 5.3
redhat
больше 8 лет назад

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

CVSS3: 9.8
nvd
больше 8 лет назад

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

suse-cvrf
больше 8 лет назад

Security update for libcares2

suse-cvrf
больше 8 лет назад

Security update for nodejs4

EPSS

Процентиль: 96%
0.22414
Средний