Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-32067

Опубликовано: 22 мая 2023
Источник: redhat
CVSS3: 7.5

Описание

c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.

A vulnerability was found in c-ares. This issue occurs due to a 0-byte UDP payload that can cause a Denial of Service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6c-aresOut of support scope
Red Hat Enterprise Linux 7c-aresFixedRHSA-2023:374121.06.2023
Red Hat Enterprise Linux 8nodejsFixedRHSA-2023:403412.07.2023
Red Hat Enterprise Linux 8nodejsFixedRHSA-2023:403512.07.2023
Red Hat Enterprise Linux 8c-aresFixedRHSA-2023:358414.06.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionsc-aresFixedRHSA-2023:366519.06.2023
Red Hat Enterprise Linux 8.2 Advanced Update Supportc-aresFixedRHSA-2023:366019.06.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicec-aresFixedRHSA-2023:366019.06.2023
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionsc-aresFixedRHSA-2023:366019.06.2023
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportc-aresFixedRHSA-2023:367720.06.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2209502c-ares: 0-byte UDP payload Denial of Service

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.

CVSS3: 7.5
nvd
около 2 лет назад

c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.

CVSS3: 7.5
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 2 лет назад

c-ares is an asynchronous resolver library. c-ares is vulnerable to de ...

rocky
почти 2 года назад

Important: c-ares security update

7.5 High

CVSS3