PT-2023-6788 · C-Ares+10 · C-Ares+10

Hannes Moesl

·

Published

2023-05-22

·

Updated

2026-02-18

·

CVE-2023-31130

CVSS v3.1

6.4

Medium

VectorAV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions c-ares versions prior to 1.19.1
Description The issue is related to a buffer underflow in the ares inet net pton() function for certain IPv6 addresses, such as "0::00:00:00/2". This function is used internally by c-ares for configuration purposes, which would require an administrator to configure such an address via ares set sortlist(). However, users may externally use ares inet net pton() for other purposes, making them vulnerable to more severe issues.
Recommendations For versions prior to 1.19.1, update to version 1.19.1 to resolve the issue. As a temporary workaround, consider restricting the use of the ares inet net pton() function for external purposes until the update is applied. Additionally, avoid using the ares set sortlist() function to configure IPv6 addresses that may cause the buffer underflow issue.

Exploit

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2023:3577
ALSA-2023:3586
ALSA-2023:4034
ALSA-2023:4035
ALSA-2023:6635
ALSA-2023:7207
ALT-PU-2023-4134
ALT-PU-2023-4623
ALT-PU-2023-5121
AZL-26914
AZL-26917
AZL-26922
AZL-26938
AZL-26940
AZL-26941
AZL-34781
AZL-43693
BDU:2023-07647
CESA-2023_4034
CESA-2023_4035
CESA-2023_7207
CVE-2023-31130
DLA-3471-1
DSA-5419-1
GHSA-X6MF-CXR9-8Q6V
OESA-2023-1357
OESA-2023-1358
OESA-2023-1359
OESA-2023-1360
OPENSUSE-SU-2024:12951-1
RHSA-2023:3577
RHSA-2023:3586
RHSA-2023:4033
RHSA-2023:4034
RHSA-2023:4035
RHSA-2023:4036
RHSA-2023:4039
RHSA-2023:6635
RHSA-2023:7207
RHSA-2023:7392
RHSA-2023:7543
RHSA-2023_3577
RHSA-2023_3586
RHSA-2023_4034
RHSA-2023_4035
RHSA-2023_6635
RHSA-2023_7207
RLSA-2023:3577
RLSA-2023:4034
RLSA-2023:4035
RLSA-2023:7207
ROSA-SA-2023-2284
SUSE-SU-2023:2313-1
SUSE-SU-2023:2477-1
SUSE-SU-2023:2655-1
SUSE-SU-2023:2662-1
SUSE-SU-2023:2663-1
SUSE-SU-2023:2669-1
SUSE-SU-2023:2861-1
USN-6164-1
USN-6164-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
C-Ares