AZL-34462

    Dashboard / Vulnerabilities / AZL-34462

    AZL-34462

    Published: 23 Feb 2024Last Modified: 21 Apr 2026
    Upstream:

    Summary: CVE-2024-25629 affecting package nodejs18 for versions less than 18.20.2-1

    Details: c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.

    Affected packages

    Package

    Name: nodejs18

    Purl: pkg:rpm/azure-linux/nodejs18

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -18.20.2-1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    AZL-34462 | CVE-DB