https://seclists.org/oss-sec/2024/q1/157: c-ares CVE-2024-25629
Published Feb 23, 2024
·Updated
Affected Software
1 affected component
c-ares c-ares<1.27.0
Frequently Asked Questions
1
What is the severity of CVE-2024-25629?
CVE-2024-25629 is considered a high severity vulnerability that affects the c-ares library.
2
How do I fix CVE-2024-25629?
To fix CVE-2024-25629, upgrade c-ares to version 1.27.0 or later, where the vulnerability has been addressed.
3
What software is affected by CVE-2024-25629?
CVE-2024-25629 affects the c-ares library, which is used for asynchronous DNS requests.
4
Are there any workarounds for CVE-2024-25629?
There are no known workarounds for CVE-2024-25629, and upgrading is recommended.
5
Who discovered CVE-2024-25629?
CVE-2024-25629 was credited to researcher Vojtěch Vobr.