Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-3584

Опубликовано: 15 июн. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-3584: c-ares security update (IMPORTANT)

[1.13.0-6.1]

  • Resolves: rhbz#2209516 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service [rhel-8.8.0.z]

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

c-ares

1.13.0-6.el8_8.2

c-ares-devel

1.13.0-6.el8_8.2

Oracle Linux x86_64

c-ares

1.13.0-6.el8_8.2

c-ares-devel

1.13.0-6.el8_8.2

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.

CVSS3: 7.5
redhat
около 2 лет назад

c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.

CVSS3: 7.5
nvd
около 2 лет назад

c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.

CVSS3: 7.5
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 2 лет назад

c-ares is an asynchronous resolver library. c-ares is vulnerable to de ...