Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000381

Опубликовано: 20 июн. 2017
Источник: redhat
CVSS3: 6.5

Описание

The c-ares function ares_parse_naptr_reply(), which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5c-aresWill not fix
Red Hat Enterprise Linux 6c-aresWill not fix
Red Hat Enterprise Linux 7c-aresWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational ToolsnodejsWill not fix
Red Hat OpenShift Enterprise 2nodejs010-nodejsWill not fix
Red Hat OpenShift Enterprise 3nodejsWill not fix
Red Hat Software Collectionsnodejs010-c-aresWill not fix
Red Hat Software Collectionsnodejs010-nodejsNot affected
Red Hat Software Collectionsrh-nodejs4-nodejsWill not fix
Red Hat Software Collectionsrh-nodejs6-nodejsAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1463132c-ares: NAPTR parser out of bounds access

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.

CVSS3: 7.5
nvd
почти 8 лет назад

The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.

CVSS3: 7.5
debian
почти 8 лет назад

The c-ares function `ares_parse_naptr_reply()`, which is used for pars ...

suse-cvrf
почти 8 лет назад

Security update for libcares2

suse-cvrf
почти 8 лет назад

Security update for libcares2

6.5 Medium

CVSS3