Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-62408

Опубликовано: 08 дек. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.9

Описание

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.

РелизСтатусПримечание
devel

pending

1.34.6-1
esm-infra/bionic

not-affected

esm-infra/focal

not-affected

esm-infra/xenial

not-affected

jammy

not-affected

1.18.1-1ubuntu0.22.04.3
noble

not-affected

1.27.0-1.0ubuntu1
plucky

released

1.34.4-2.1ubuntu0.2
questing

released

1.34.5-1ubuntu0.1
upstream

released

1.34.6-1

Показывать по

EPSS

Процентиль: 19%
0.0006
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
около 2 месяцев назад

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.

CVSS3: 5.9
msrc
около 2 месяцев назад

c-ares has a Use After Free vulnerability when connection is cleaned up after error

CVSS3: 5.9
debian
около 2 месяцев назад

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1. ...

EPSS

Процентиль: 19%
0.0006
Низкий

5.9 Medium

CVSS3