Lucene search

K
redhatcveRedhat.comRH:CVE-2020-14354
HistoryAug 12, 2020 - 2:43 p.m.

CVE-2020-14354

2020-08-1214:43:33
redhat.com
access.redhat.com
7

0.001 Low

EPSS

Percentile

21.3%

A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service that uses c-ares lib. The highest threat from this vulnerability is to this service availability.

Mitigation

If calling wait_ares(channel) before ares_destroy() in the service that uses c-ares, then this should prevent this bug.

0.001 Low

EPSS

Percentile

21.3%