Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-31124
HistoryMay 25, 2023 - 10:15 p.m.

Cross site scripting

2023-05-2522:15:00
PRIOn knowledge base
www.prio-n.com
8
cross site scripting
c-ares
asynchronous resolver
autotools
entropy
csprng
patch
nvd
aarch64 android

5.2 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

39.8%

c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1.

CPENameOperatorVersion
c-areslt1.19.1
fedoraeq37
fedoraeq38