Логотип exploitDog
bind:CVE-2024-25629
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-25629

Количество 18

Количество 18

ubuntu логотип

CVE-2024-25629

больше 1 года назад

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2024-25629

больше 1 года назад

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2024-25629

больше 1 года назад

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.

CVSS3: 4.4
EPSS: Низкий
msrc логотип

CVE-2024-25629

8 месяцев назад

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2024-25629

больше 1 года назад

c-ares is a C library for asynchronous DNS requests. `ares__read_line( ...

CVSS3: 4.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1136-1

около 1 года назад

Security update for c-ares

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1135-1

около 1 года назад

Security update for libcares2

EPSS: Низкий
rocky логотип

RLSA-2024:4249

около 1 месяца назад

Low: c-ares security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4249

12 месяцев назад

ELSA-2024-4249: c-ares security update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3842

около 1 года назад

ELSA-2024-3842: c-ares security update (LOW)

EPSS: Низкий
fstec логотип

BDU:2024-01708

больше 1 года назад

Уязвимость функции ares__read_line библиотеки асинхронных DNS-запросов C-ares, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.4
EPSS: Низкий
redos логотип

ROS-20240410-04

около 1 года назад

Множественные уязвимости с-ares

CVSS3: 4.4
EPSS: Низкий
rocky логотип

RLSA-2024:2910

около 1 года назад

Important: nodejs security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2910

около 1 года назад

ELSA-2024-2910: nodejs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2853

около 1 года назад

ELSA-2024-2853: nodejs:20 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2780

около 1 года назад

ELSA-2024-2780: nodejs:18 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2779

около 1 года назад

ELSA-2024-2779: nodejs:18 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2778

около 1 года назад

ELSA-2024-2778: nodejs:20 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-25629

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-25629

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-25629

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 5.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-25629

c-ares is a C library for asynchronous DNS requests. `ares__read_line( ...

CVSS3: 4.4
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1136-1

Security update for c-ares

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1135-1

Security update for libcares2

0%
Низкий
около 1 года назад
rocky логотип
RLSA-2024:4249

Low: c-ares security update

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2024-4249

ELSA-2024-4249: c-ares security update (LOW)

12 месяцев назад
oracle-oval логотип
ELSA-2024-3842

ELSA-2024-3842: c-ares security update (LOW)

около 1 года назад
fstec логотип
BDU:2024-01708

Уязвимость функции ares__read_line библиотеки асинхронных DNS-запросов C-ares, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.4
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240410-04

Множественные уязвимости с-ares

CVSS3: 4.4
0%
Низкий
около 1 года назад
rocky логотип
RLSA-2024:2910

Important: nodejs security update

около 1 года назад
oracle-oval логотип
ELSA-2024-2910

ELSA-2024-2910: nodejs security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2024-2853

ELSA-2024-2853: nodejs:20 security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2024-2780

ELSA-2024-2780: nodejs:18 security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2024-2779

ELSA-2024-2779: nodejs:18 security update (IMPORTANT)

около 1 года назад
oracle-oval логотип
ELSA-2024-2778

ELSA-2024-2778: nodejs:20 security update (IMPORTANT)

около 1 года назад

Уязвимостей на страницу