[FREEBSD:43E9FFD4-D6E0-11ED-956F-7054D21A9E2A] py39-pycares -- domain hijacking vulnerability

Severity Medium
Affected Packages 1
CVEs 1

Philipp Jeitner and Haya Shulman report:

  A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking.
  The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
Package Affected Version
pkg:freebsd/py39-pycares < 4.2.0
Source # ID Name URL
FreeBSD VuXML https://osv.dev/vulnerability/GHSA-c58j-88f5-h53f
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/py39-pycares py39-pycares < 4.2.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date