Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-31124

Опубликовано: 25 мая 2023
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS3: 3.7

Описание

c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

esm-infra/bionic

not-affected

esm-infra/focal

not-affected

esm-infra/xenial

not-affected

focal

not-affected

jammy

not-affected

kinetic

not-affected

lunar

not-affected

trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 22%
0.0007
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
около 2 лет назад

c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1.

CVSS3: 3.7
nvd
около 2 лет назад

c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1.

CVSS3: 3.7
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 3.7
debian
около 2 лет назад

c-ares is an asynchronous resolver library. When cross-compiling c-are ...

CVSS3: 3.7
fstec
около 2 лет назад

Уязвимость компонента autotools CARES_RANDOM_FILE библиотеки асинхронных DNS-запросов C-ares, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 22%
0.0007
Низкий

3.7 Low

CVSS3