Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-62408

Опубликовано: 08 дек. 2025
Источник: debian

Описание

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
c-aresfixed1.34.6-1package
c-aresnot-affectedbookwormpackage
c-aresnot-affectedbullseyepackage

Примечания

  • https://github.com/c-ares/c-ares/security/advisories/GHSA-jq53-42q6-pqr5

  • Fixed by: https://github.com/c-ares/c-ares/commit/714bf5675c541bd1e668a8db8e67ce012651e618 (main)

  • Fixed by: https://github.com/c-ares/c-ares/commit/abf004903696383bf701b77b87f2a7ed7aaa1276 (v1.34.6)

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 2 месяцев назад

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.

CVSS3: 5.9
nvd
около 2 месяцев назад

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.

CVSS3: 5.9
msrc
около 2 месяцев назад

c-ares has a Use After Free vulnerability when connection is cleaned up after error