AZL-34463

    Dashboard / Vulnerabilities / AZL-34463

    AZL-34463

    Published: 23 Feb 2024Last Modified: 21 Apr 2026
    Upstream:

    Summary: CVE-2024-25629 affecting package python-gevent for versions less than 21.1.2-3

    Details: c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.

    Affected packages

    Package

    Name: python-gevent

    Purl: pkg:rpm/azure-linux/python-gevent

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -21.1.2-3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    AZL-34463 | CVE-DB