Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-4904

Опубликовано: 06 мар. 2023
Источник: debian

Описание

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
c-aresfixed1.18.1-2package
c-aresfixed1.17.1-1+deb11u2bullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2168631

  • https://github.com/c-ares/c-ares/pull/497

  • https://github.com/c-ares/c-ares/commit/9903253c347f9e0bffd285ae3829aef251cc852d (cares-1_19_0)

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 2 лет назад

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

CVSS3: 8.6
redhat
больше 2 лет назад

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

CVSS3: 8.6
nvd
больше 2 лет назад

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.

CVSS3: 8.6
msrc
больше 2 лет назад

Описание отсутствует

suse-cvrf
почти 2 года назад

Security update for libcares2