Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-31124

Опубликовано: 22 мая 2023
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1.

A flaw was found in c-ares. This issue occurs when cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross-compiling aarch64 android. As a result, it will downgrade to rand(), which could allow an attacker to utilize the lack of entropy by not using a CSPRNG.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6c-aresOut of support scope
Red Hat Enterprise Linux 7c-aresOut of support scope
Red Hat Enterprise Linux 8c-aresFix deferred
Red Hat Enterprise Linux 8nodejsFixedRHSA-2023:403412.07.2023
Red Hat Enterprise Linux 8nodejsFixedRHSA-2023:403512.07.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportnodejsFixedRHSA-2023:403312.07.2023
Red Hat Enterprise Linux 9nodejsFixedRHSA-2023:357714.06.2023
Red Hat Enterprise Linux 9nodejsFixedRHSA-2023:358614.06.2023
Red Hat Enterprise Linux 9c-aresFixedRHSA-2023:663507.11.2023
Red Hat Enterprise Linux 9c-aresFixedRHSA-2023:663507.11.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-330
https://bugzilla.redhat.com/show_bug.cgi?id=2209494c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation

EPSS

Процентиль: 22%
0.0007
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 2 лет назад

c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1.

CVSS3: 3.7
nvd
около 2 лет назад

c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1.

CVSS3: 3.7
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 3.7
debian
около 2 лет назад

c-ares is an asynchronous resolver library. When cross-compiling c-are ...

CVSS3: 3.7
fstec
около 2 лет назад

Уязвимость компонента autotools CARES_RANDOM_FILE библиотеки асинхронных DNS-запросов C-ares, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 22%
0.0007
Низкий

3.7 Low

CVSS3