Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5180

Опубликовано: 03 окт. 2016
Источник: debian

Описание

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
c-aresfixed1.12.0-1package

Примечания

  • https://c-ares.haxx.se/adv_20160929.html

  • https://c-ares.haxx.se/CVE-2016-5180.patch

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

CVSS3: 5.3
redhat
почти 9 лет назад

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

CVSS3: 9.8
nvd
почти 9 лет назад

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

suse-cvrf
больше 8 лет назад

Security update for libcares2

suse-cvrf
больше 8 лет назад

Security update for nodejs4