Lucene search

K
cvelistRedhatCVELIST:CVE-2020-14354
HistoryMay 13, 2021 - 1:38 p.m.

CVE-2020-14354

2021-05-1313:38:56
CWE-120
redhat
www.cve.org
1

3.9 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.3%

A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service that uses c-ares lib. The highest threat from this vulnerability is to this service availability.

CNA Affected

[
  {
    "product": "c-ares",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "c-ares 1.16.1"
      }
    ]
  }
]

3.9 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.3%