openSUSE-SU-2021:2760-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:2760-1
openSUSE-SU-2021:2760-1
Summary: Security update for c-ares
Details: This update for c-ares fixes the following issues: Version update to git snapshot 1.17.1+20200724: - CVE-2021-3672: fixed missing input validation on hostnames returned by DNS servers (bsc#1188881) - If ares_getaddrinfo() was terminated by an ares_destroy(), it would cause crash - Crash in sortaddrinfo() if the list size equals 0 due to an unexpected DNS response - Expand number of escaped characters in DNS replies as per RFC1035 5.1 to prevent spoofing - Use unbuffered /dev/urandom for random data to prevent early startup performance issues
References: https://lists.opensuse.org/archives/list/[email protected]/thread/4F2ZKNNMGENSNMAS5CDHA3CDDRAXF3AQ/, https://bugzilla.suse.com/1188881, https://www.suse.com/security/cve/CVE-2021-3672
Affected packages
Package
Name: c-ares
Purl: pkg:rpm/opensuse/c-ares&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
