USN-6676-1: c-ares vulnerability
Published Mar 6, 2024
·Updated
Vojtěch Vobr discovered that c-ares incorrectly handled user input from local configuration files. An attacker could possibly use this issue to cause a denial of service via application crash.
Affected Software
10 affected componentsFixes available
All of the following
ubuntu/libc-ares2<1.19.1-3ubuntu0.1
1.19.1-3ubuntu0.1
Ubuntu Ubuntu=23.10
All of the following
ubuntu/libc-ares2<1.18.1-1ubuntu0.22.04.3
1.18.1-1ubuntu0.22.04.3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libc-ares2<1.15.0-1ubuntu0.5
1.15.0-1ubuntu0.5
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libc-ares2<1.14.0-1ubuntu0.2+esm2
1.14.0-1ubuntu0.2+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libc-ares2<1.10.0-3ubuntu0.2+esm3
1.10.0-3ubuntu0.2+esm3
Ubuntu Ubuntu=16.04
Event History
Mar 6, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6676-1?
USN-6676-1 is considered a denial of service vulnerability that can lead to application crashes.
2
How do I fix USN-6676-1?
To fix USN-6676-1, update libc-ares2 to the recommended version for your Ubuntu distribution.
3
What versions of Ubuntu are affected by USN-6676-1?
USN-6676-1 affects Ubuntu versions 23.10, 22.04, 20.04, 18.04, and 16.04.
4
What is CVE-2024-25629 related to USN-6676-1?
CVE-2024-25629 is the identifier for the vulnerability reported in USN-6676-1 affecting libc-ares.
5
Can USN-6676-1 be exploited remotely?
Yes, an attacker can exploit USN-6676-1 to cause a denial of service via specially crafted input.