CVE-2021-3672: XSS
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
Other sources
Missing input validation of host names returned by Domain Name Servers in the c-ares library can lead to output of wrong hostnames (leading to Domain Hijacking).
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-3672?
CVE-2021-3672 is a vulnerability in the c-ares library that allows for potential domain hijacking due to a missing input validation check of host names returned by DNS.
What is the severity of CVE-2021-3672?
The severity of CVE-2021-3672 is medium, with a severity score of 5.6.
Which software is affected by CVE-2021-3672?
The c-ares library versions up to and excluding 1.17.2 and specific versions of the rh-nodejs14-nodejs, rh-nodejs12-nodejs, and rh-nodejs12-nodejs-nodemon packages are affected.
How can I fix the CVE-2021-3672 vulnerability?
To fix the CVE-2021-3672 vulnerability, update the c-ares library to version 1.17.2 or higher.
Where can I find more information about CVE-2021-3672?
You can find more information about CVE-2021-3672 in the following references: [Bugzilla: 1992221](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1992221), [Bugzilla: 1992222](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1992222), [c-ares Advisory](https://c-ares.haxx.se/adv_20210810.html).