SUSE-SU-2021:2760-1
Dashboard / Vulnerabilities / SUSE-SU-2021:2760-1
SUSE-SU-2021:2760-1
Summary: Security update for c-ares
Details: This update for c-ares fixes the following issues: Version update to git snapshot 1.17.1+20200724: - CVE-2021-3672: fixed missing input validation on hostnames returned by DNS servers (bsc#1188881) - If ares_getaddrinfo() was terminated by an ares_destroy(), it would cause crash - Crash in sortaddrinfo() if the list size equals 0 due to an unexpected DNS response - Expand number of escaped characters in DNS replies as per RFC1035 5.1 to prevent spoofing - Use unbuffered /dev/urandom for random data to prevent early startup performance issues
References: https://www.suse.com/support/update/announcement/2021/suse-su-20212760-1/, https://bugzilla.suse.com/1188881, https://www.suse.com/security/cve/CVE-2021-3672
Affected packages
Package
Name: c-ares
Purl: pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
