Lucene search

K
mageiaGentoo FoundationMGASA-2023-0069
HistoryFeb 27, 2023 - 11:27 p.m.

Updated c-ares packages fix security vulnerability

2023-02-2723:27:16
Gentoo Foundation
advisories.mageia.org
17
c-ares
security vulnerability
config_sortlist
input string
stack overflow
denial of service
unix

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

0.001 Low

EPSS

Percentile

26.2%

The config_sortlist function is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow and thus may cause a denial of service. (CVE-2022-4904)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchc-ares< 1.17.1-1.2c-ares-1.17.1-1.2.mga8

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

0.001 Low

EPSS

Percentile

26.2%