[GLSA-202401-02] c-ares: Multiple Vulnerabilities

Severity Normal
Affected Packages 1
Unaffected Packages 1
CVEs 6

Multiple vulnerabilities have been found in c-ares, the worst of which could result in the loss of confidentiality or integrity.

Background
c-ares is a C library for asynchronous DNS requests (including name resolves).

Description
Multiple vulnerabilities have been discovered in c-ares. Please review the CVE identifiers referenced below for details.

Impact
Please review the referenced CVE identifiers for details.

Workaround
There is no known workaround at this time.

Resolution
All c-ares users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-dns/c-ares-1.19.0"

Package Affected Version
pkg:ebuild/net-dns/c-ares?distro=gentoo < 1.19.0
Package Unaffected Version
pkg:ebuild/net-dns/c-ares?distro=gentoo >= 1.19.0
ID
GLSA-202401-02
Severity
normal
URL
https://security.gentoo.org/glsa/202401-02
Published
2024-01-05T00:00:00
(8 months ago)
Modified
2024-01-05T00:00:00
(8 months ago)
Rights
Gentoo Foundation, Inc.
Other Advisories
Source # ID Name URL
CVE CVE-2021-3672 CVE-2021-3672 https://nvd.nist.gov/vuln/detail/CVE-2021-3672
CVE CVE-2021-22930 CVE-2021-22930 https://nvd.nist.gov/vuln/detail/CVE-2021-22930
CVE CVE-2021-22931 CVE-2021-22931 https://nvd.nist.gov/vuln/detail/CVE-2021-22931
CVE CVE-2021-22939 CVE-2021-22939 https://nvd.nist.gov/vuln/detail/CVE-2021-22939
CVE CVE-2021-22940 CVE-2021-22940 https://nvd.nist.gov/vuln/detail/CVE-2021-22940
CVE CVE-2022-4904 CVE-2022-4904 https://nvd.nist.gov/vuln/detail/CVE-2022-4904
Bugzilla 807604 Bugzilla #807604 https://bugs.gentoo.org/show_bug.cgi?id=807604
Bugzilla 807775 Bugzilla #807775 https://bugs.gentoo.org/show_bug.cgi?id=807775
Bugzilla 892489 Bugzilla #892489 https://bugs.gentoo.org/show_bug.cgi?id=892489
Bugzilla 905341 Bugzilla #905341 https://bugs.gentoo.org/show_bug.cgi?id=905341
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/net-dns/c-ares?distro=gentoo net-dns c-ares < 1.19.0 gentoo
Unaffected pkg:ebuild/net-dns/c-ares?distro=gentoo net-dns c-ares >= 1.19.0 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...