Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-32067
HistoryMay 25, 2023 - 12:00 a.m.

CVE-2023-32067

2023-05-2500:00:00
ubuntu.com
ubuntu.com
19
asynchronous resolver library
udp packet
target resolver
graceful shutdown
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

48.7%

c-ares is an asynchronous resolver library. c-ares is vulnerable to denial
of service. If a target resolver sends a query, the attacker forges a
malformed UDP packet with a length of 0 and returns them to the target
resolver. The target resolver erroneously interprets the 0 length as a
graceful shutdown of the connection. This issue has been patched in version
1.19.1.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchc-ares< 1.14.0-1ubuntu0.2+esm1UNKNOWN
ubuntu20.04noarchc-ares< 1.15.0-1ubuntu0.3UNKNOWN
ubuntu22.04noarchc-ares< 1.18.1-1ubuntu0.22.04.2UNKNOWN
ubuntu22.10noarchc-ares< 1.18.1-1ubuntu0.22.10.2UNKNOWN
ubuntu23.04noarchc-ares< 1.18.1-2ubuntu0.1UNKNOWN
ubuntu16.04noarchc-ares< 1.10.0-3ubuntu0.2+esm2UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

48.7%