PT-2023-6789 · C-Ares+10 · C-Ares+10

Xiang Li

·

Published

2023-05-22

·

Updated

2026-02-18

·

CVE-2023-32067

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions c-ares versions prior to 1.19.1
Description The issue is related to a denial of service vulnerability in the c-ares library, which is an asynchronous resolver library. It occurs when a target resolver sends a query, and an attacker forges a malformed UDP packet with a length of 0, causing the target resolver to interpret the 0 length as a graceful shutdown of the connection. This can lead to a denial of service.
Recommendations For versions prior to 1.19.1, update to version 1.19.1 to resolve the issue. As a temporary workaround, consider restricting the handling of UDP packets with a length of 0 to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2023:3559
ALSA-2023:3577
ALSA-2023:3584
ALSA-2023:3586
ALSA-2023:4034
ALSA-2023:4035
ALT-PU-2023-4134
ALT-PU-2023-4623
ALT-PU-2023-5121
AZL-26913
AZL-26918
AZL-26921
AZL-26937
AZL-26939
AZL-26942
AZL-34782
AZL-43924
BDU:2023-07649
CESA-2023_3584
CESA-2023_3741
CESA-2023_4034
CESA-2023_4035
CVE-2023-32067
DLA-3471-1
DSA-5419-1
GHSA-9G78-JV2R-P7VC
OESA-2023-1302
OESA-2023-1311
OESA-2023-1312
OESA-2023-1313
OESA-2023-1314
OPENSUSE-SU-2024:12951-1
RHSA-2023:3559
RHSA-2023:3577
RHSA-2023:3583
RHSA-2023:3584
RHSA-2023:3586
RHSA-2023:3660
RHSA-2023:3662
RHSA-2023:3665
RHSA-2023:3677
RHSA-2023:3741
RHSA-2023:4033
RHSA-2023:4034
RHSA-2023:4035
RHSA-2023:4036
RHSA-2023:4039
RHSA-2023_3559
RHSA-2023_3577
RHSA-2023_3584
RHSA-2023_3586
RHSA-2023_3741
RHSA-2023_4034
RHSA-2023_4035
RLSA-2023:3559
RLSA-2023:3577
RLSA-2023:3584
RLSA-2023:4034
RLSA-2023:4035
ROSA-SA-2023-2190
SUSE-SU-2023:2313-1
SUSE-SU-2023:2477-1
SUSE-SU-2023:2655-1
SUSE-SU-2023:2662-1
SUSE-SU-2023:2663-1
SUSE-SU-2023:2669-1
SUSE-SU-2023:2861-1
USN-6164-1
USN-6164-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
C-Ares