UBUNTU-CVE-2023-31130
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-31130
UBUNTU-CVE-2023-31130
Summary:
Details: c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an address via ares_set_sortlist(). However, users may externally use ares_inet_net_pton() for other purposes and thus be vulnerable to more severe issues. This issue has been fixed in 1.19.1.
References: https://ubuntu.com/security/CVE-2023-31130, https://github.com/c-ares/c-ares/security/advisories/GHSA-x6mf-cxr9-8q6v, https://www.openwall.com/lists/oss-security/2023/05/22/2, https://ubuntu.com/security/notices/USN-6164-1, https://ubuntu.com/security/notices/USN-6164-2, https://www.cve.org/CVERecord?id=CVE-2023-31130
Affected packages
Package
Name: c-ares
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
