USN-6376-1: c-ares vulnerability
Published Sep 18, 2023
·Updated
It was discovered that c-ares incorrectly parsed certain SOA replies. A remote attacker could possibly use this issue to cause c-res to crash, resulting in a denial of service.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/libc-ares2<1.15.0-1ubuntu0.4
1.15.0-1ubuntu0.4
Ubuntu Ubuntu=20.04
Event History
Sep 18, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this c-ares vulnerability?
The vulnerability ID for this c-ares vulnerability is CVE-2020-22217.
2
What is the impact of the c-ares vulnerability?
The c-ares vulnerability can result in a denial of service by causing c-ares to crash.
3
Which software versions are affected by this c-ares vulnerability?
The affected software version is libc-ares2 1.15.0-1ubuntu0.4 on Ubuntu 20.04.
4
How can I fix the c-ares vulnerability?
To fix the c-ares vulnerability, you should update libc-ares2 to version 1.15.0-1ubuntu0.4.
5
Where can I find more information about the c-ares vulnerability?
You can find more information about the c-ares vulnerability in the Ubuntu Security Notice USN-6376-1.