CVE-2020-22217: Buffer Overflow
Buffer overflow vulnerability in c-ares before 1161 thru 1170 via function aresparsesoareply in aresparsesoareply.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/c-aresto a version that resolves this vulnerability.Fixed in 1.14.0-1+deb10u4Fixed in 1.17.1-1+deb11u3Fixed in 1.18.1-3Fixed in 1.27.0-1 - Upgrade
Upgrade
ubuntu/c-aresto a version that resolves this vulnerability.Fixed in 1.15.0-1ubuntu0.4 - Upgrade
Upgrade
redhat/c-aresto a version that resolves this vulnerability.Fixed in 1.17.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 21.1.2-1
Event History
Frequently Asked Questions
What is CVE-2020-22217?
CVE-2020-22217 is a buffer overflow vulnerability in c-ares, specifically in the function ares_parse_soa_reply.
How severe is CVE-2020-22217?
CVE-2020-22217 has a severity rating of 9.8 (Critical).
Which versions of c-ares are affected by CVE-2020-22217?
Versions c-ares 1.16.1 through 1.17.0 are affected by CVE-2020-22217.
How can I fix CVE-2020-22217?
To fix CVE-2020-22217, update c-ares to version 1.17.1-1+deb11u2 or later.
Where can I find more information about CVE-2020-22217?
You can find more information about CVE-2020-22217 on the GitHub issue page and the Debian LTS announcement.