PT-2024-1920 · C-Ares+9 · C-Ares+9

Vojtechvobr

·

Published

2024-02-23

·

Updated

2025-09-29

·

CVE-2024-25629

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions c-ares versions prior to 1.27.0
Description The issue is related to the ares read line() function in the c-ares library, which is used for asynchronous DNS requests. This function parses local configuration files such as /etc/resolv.conf, /etc/nsswitch.conf, the HOSTALIASES file, and if using a c-ares version prior to 1.27.0, the /etc/hosts file. If any of these configuration files has an embedded NULL character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer, which may result in a crash. This can be exploited to cause a denial of service.
Recommendations For c-ares versions prior to 1.27.0, update to version 1.27.0 to fix the issue. As a temporary workaround, consider restricting access to the configuration files to prevent exploitation. Avoid using configuration files with embedded NULL characters.

Exploit

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2024:2778
ALSA-2024:2779
ALSA-2024:2780
ALSA-2024:2853
ALSA-2024:2910
ALSA-2024:3842
ALSA-2024:4249
ALSA-2024_2778
ALSA-2024_2779
ALSA-2024_2780
ALSA-2024_2853
ALSA-2024_2910
ALSA-2024_3842
ALSA-2024_4249
ALSA-2025_16880
AZL-34453
AZL-34455
AZL-34456
AZL-34462
AZL-34463
AZL-34578
AZL-34687
AZL-35048
AZL-35132
AZL-38126
AZL-43501
BDU:2024-01708
CESA-2024_2778
CESA-2024_2780
CESA-2024_4249
CVE-2024-25629
GHSA-MG26-V6QH-X48Q
INFSA-2024_2779
INFSA-2024_2853
INFSA-2024_2910
INFSA-2024_3842
INFSA-2024_4249
MGASA-2024-0051
OESA-2024-2019
OESA-2024-2020
OESA-2024-2021
OPENSUSE-SU-2024:13722-1
OPENSUSE-SU-2024_1136-1
RHSA-2024:2778
RHSA-2024:2779
RHSA-2024:2780
RHSA-2024:2853
RHSA-2024:2910
RHSA-2024:3842
RHSA-2024:4249
RHSA-2024:4559
RHSA-2024:4721
RHSA-2024_2778
RHSA-2024_2779
RHSA-2024_2780
RHSA-2024_2853
RHSA-2024_2910
RHSA-2024_3842
RHSA-2024_4249
RLSA-2024:2778
RLSA-2024:2779
RLSA-2024:2780
RLSA-2024:2853
RLSA-2024:2910
SUSE-SU-2024:1135-1
SUSE-SU-2024:1136-1
SUSE-SU-2024:1136-2
SUSE-SU-2024_1135-1
SUSE-SU-2024_1136-1
USN-6676-1

Affected Products

Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
C-Ares