Описание
Security update for c-ares
This update for c-ares fixes the following issue
- CVE-2025-62408: use after free in read_answers() (bsc#1254738).
Changes for c-ares:
- c-ares 1.35.6:
- Ignore Windows IDN Search Domains until proper IDN support is added
- Various bug fixes
Список пакетов
openSUSE Leap 16.0
c-ares-devel-1.34.6-160000.1.1
c-ares-utils-1.34.6-160000.1.1
libcares2-1.34.6-160000.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1254738
- SUSE CVE CVE-2025-62408 page
Описание
c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.
Затронутые продукты
openSUSE Leap 16.0:c-ares-devel-1.34.6-160000.1.1
openSUSE Leap 16.0:c-ares-utils-1.34.6-160000.1.1
openSUSE Leap 16.0:libcares2-1.34.6-160000.1.1
Ссылки
- CVE-2025-62408
- SUSE Bug 1254738