Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:2043

Опубликовано: 10 мая 2022
Источник: rocky
Оценка: Moderate

Описание

Moderate: c-ares security update

The c-ares C library defines asynchronous DNS (Domain Name System) requests and provides name resolving API.

Security Fix(es):

  • c-ares: Missing input validation of host names may lead to domain hijacking (CVE-2021-3672)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
c-aresx86_646.el8c-ares-1.13.0-6.el8.x86_64.rpm
c-ares-develx86_646.el8c-ares-devel-1.13.0-6.el8.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 3 лет назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
redhat
почти 4 года назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
nvd
больше 3 лет назад

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

CVSS3: 5.6
msrc
4 месяца назад

Описание отсутствует

CVSS3: 5.6
debian
больше 3 лет назад

A flaw was found in c-ares library, where a missing input validation c ...