PT-2020-6913 · C-Ares+9 · C-Ares+9

Ltx2018

·

Published

2020-05-21

·

Updated

2026-02-18

·

CVE-2020-22217

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions c-ares versions 1 16 1 through 1 17 0
Description The issue is related to a buffer overflow vulnerability in the ares parse soa reply() function of the c-ares library, which handles asynchronous DNS requests. This vulnerability can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For c-ares versions 1 16 1 through 1 17 0, update to version 1 17 1 or later to resolve the issue. As a temporary workaround, consider disabling the ares parse soa reply() function until a patch is available.

Exploit

Fix

Out of bounds Read

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2023:7207
ALT-PU-2020-3198
ALT-PU-2020-4216
ALT-PU-2021-4838
ALT-PU-2022-3071
ALT-PU-2023-5121
AZL-28597
BDU:2023-05898
CESA-2023_7207
CVE-2020-22217
DLA-3567-1
RHSA-2023:7207
RHSA-2023_7207
RHSA-2024:0419
RHSA-2024:0578
RLSA-2023:7207
SUSE-SU-2023:3690-1
SUSE-SU-2023_3690-1
USN-6376-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
C-Ares