PT-2016-6298 · C-Ares+3 · C-Ares+3

Gzob Qq

·

Publicado

2016-07-15

·

Atualizado

2024-06-15

·

CVE-2016-5180

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions c-ares versions 1.x before 1.12.0
Description The issue is related to a heap-based buffer overflow in the ares create query function, which can be triggered by a remote attacker using a hostname with an escaped trailing dot. This can lead to a denial of service due to an out-of-bounds write or potentially allow the execution of arbitrary code.
Recommendations For versions prior to 1.12.0, update to version 1.12.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of hostnames with escaped trailing dots to minimize the risk of exploitation.

Exploit

Correção

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1759
ALT-PU-2016-3244
ALT-PU-2017-2000
ALT-PU-2018-2653
ALT-PU-2020-3198
ALT-PU-2022-3071
ALT-PU-2023-5121
CVE-2016-5180
DLA-648-1
DSA-3682-1
MGASA-2016-0351
OPENSUSE-SU-2024:10147-1
OPENSUSE-SU-2024:10247-1
RHSA-2017:0002
SUSE-SU-2016:2898-1
SUSE-SU-2016:3286-1
SUSE-SU-2016:3287-1
SUSE-SU-2016_2898-1
SUSE-SU-2016_3286-1
SUSE-SU-2016_3287-1
USN-3143-1

Produtos afetados

Alt Linux
Suse
Ubuntu
C-Ares