[ALAS2-2024-2429] Amazon Linux 2 2017.12 - ALAS2-2024-2429: low priority package update for c-ares

Severity Low
Affected Packages 9
CVEs 1

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2023-31124:
When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/c-ares?arch=x86_64&distro=amazonlinux-2 amazonlinux c-ares < 1.10.0-3.amzn2.0.5 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/c-ares?arch=i686&distro=amazonlinux-2 amazonlinux c-ares < 1.10.0-3.amzn2.0.5 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/c-ares?arch=aarch64&distro=amazonlinux-2 amazonlinux c-ares < 1.10.0-3.amzn2.0.5 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/c-ares-devel?arch=x86_64&distro=amazonlinux-2 amazonlinux c-ares-devel < 1.10.0-3.amzn2.0.5 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/c-ares-devel?arch=i686&distro=amazonlinux-2 amazonlinux c-ares-devel < 1.10.0-3.amzn2.0.5 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/c-ares-devel?arch=aarch64&distro=amazonlinux-2 amazonlinux c-ares-devel < 1.10.0-3.amzn2.0.5 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/c-ares-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux c-ares-debuginfo < 1.10.0-3.amzn2.0.5 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/c-ares-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux c-ares-debuginfo < 1.10.0-3.amzn2.0.5 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/c-ares-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux c-ares-debuginfo < 1.10.0-3.amzn2.0.5 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...