Описание
Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.
A heap buffer over-read flaw was found in c-ares via the ares_parse_soa_reply function in ares_parse_soa_reply.c.
Отчет
The attack vector for this flaw initiates from a malicious server (a SOA reply to a client query) which requires a attacker set up a server a make it to be queried by a victim through cache poisoning or MITM, raising the Attack Complexity to High. This being a out of bounds reads does not bring a risk of memory corruption, which makes it of none impact to Integrity. Also the read limitis 2 bytes (16bit, unsigned short int) from the DNS_QUERY_TYPE MACRO[1] return and the read value would be ignored and not propagated anywhere since the subsequent check would also fail making the confidentiality impact as none. [1] https://github.com/c-ares/c-ares/blob/4d4fb34075c90d8f2f9ff81890152ab60f65e48e/include/ares_dns.h#L95 [2] https://github.com/c-ares/c-ares/issues/333
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/ee-supported-rhel8 | Not affected | ||
Red Hat Enterprise Linux 6 | c-ares | Out of support scope | ||
Red Hat Enterprise Linux 7 | c-ares | Out of support scope | ||
Red Hat Enterprise Linux 8 | nodejs:16/nodejs | Not affected | ||
Red Hat Enterprise Linux 8 | nodejs:18/nodejs | Not affected | ||
Red Hat Enterprise Linux 8 | nodejs:20/nodejs | Not affected | ||
Red Hat Enterprise Linux 9 | c-ares | Not affected | ||
Red Hat Enterprise Linux 9 | nodejs | Not affected | ||
Red Hat Enterprise Linux 9 | nodejs:18/nodejs | Not affected | ||
Red Hat Enterprise Linux 9 | nodejs:20/nodejs | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.
Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.
Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via ...
EPSS
5.9 Medium
CVSS3