[USN-5034-1] c-ares vulnerability
Severity
Medium
Affected Packages
6
CVEs
1
c-ares could be made to return wrong domains.
Philipp Jeitner and Haya Shulman discovered that c-ares incorrectly
validated certain hostnames returned by DNS servers. A remote attacker
could possibly use this issue to perform Domain Hijacking attacks.
Package | Affected Version |
---|---|
pkg:deb/ubuntu/libc-ares2?distro=hirsute | < 1.17.1-1ubuntu0.1 |
pkg:deb/ubuntu/libc-ares2?distro=focal | < 1.15.0-1ubuntu0.1 |
pkg:deb/ubuntu/libc-ares2?distro=bionic | < 1.14.0-1ubuntu0.1 |
pkg:deb/ubuntu/libc-ares-dev?distro=hirsute | < 1.17.1-1ubuntu0.1 |
pkg:deb/ubuntu/libc-ares-dev?distro=focal | < 1.15.0-1ubuntu0.1 |
pkg:deb/ubuntu/libc-ares-dev?distro=bionic | < 1.14.0-1ubuntu0.1 |
- ID
- USN-5034-1
- Severity
- medium
- URL
- https://ubuntu.com/security/notices/USN-5034-1
- Published
-
2021-08-10T11:53:27
(3 years ago) - Modified
-
2021-08-10T11:53:27
(3 years ago) - Other Advisories
-
- ALAS-2021-1545
- ALAS2-2024-2399
- ALPINE:CVE-2021-3672
- ALSA-2021:3623
- ALSA-2021:3666
- ALSA-2022:2043
- ASA-202108-13
- DSA-4954-1
- ELSA-2021-3623
- ELSA-2021-3666
- ELSA-2022-2043
- FEDORA-2021-001ec24fc5
- FEDORA-2021-0a60cbb948
- FEDORA-2021-52c89b44a9
- FEDORA-2021-a48cf28c13
- FEDORA-2021-c83b66abdb
- FREEBSD:43E9FFD4-D6E0-11ED-956F-7054D21A9E2A
- GLSA-202401-02
- GLSA-202405-29
- MS:CVE-2021-3672
- openSUSE-SU-2021:1168-1
- openSUSE-SU-2021:1214-1
- openSUSE-SU-2021:1239-1
- openSUSE-SU-2021:1313-1
- openSUSE-SU-2021:2760-1
- openSUSE-SU-2021:2875-1
- openSUSE-SU-2021:2953-1
- openSUSE-SU-2021:3211-1
- RHSA-2021:3623
- RHSA-2021:3666
- RHSA-2022:2043
- RLSA-2021:3623
- RLSA-2021:3666
- RLSA-2022:2043
- SUSE-SU-2021:2690-1
- SUSE-SU-2021:2760-1
- SUSE-SU-2021:2823-1
- SUSE-SU-2021:2824-1
- SUSE-SU-2021:2875-1
- SUSE-SU-2021:2953-1
- SUSE-SU-2021:3184-1
- SUSE-SU-2021:3211-1
- USN-5034-2
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:deb/ubuntu/libc-ares2?distro=hirsute | ubuntu | libc-ares2 | < 1.17.1-1ubuntu0.1 | hirsute | ||
Affected | pkg:deb/ubuntu/libc-ares2?distro=focal | ubuntu | libc-ares2 | < 1.15.0-1ubuntu0.1 | focal | ||
Affected | pkg:deb/ubuntu/libc-ares2?distro=bionic | ubuntu | libc-ares2 | < 1.14.0-1ubuntu0.1 | bionic | ||
Affected | pkg:deb/ubuntu/libc-ares-dev?distro=hirsute | ubuntu | libc-ares-dev | < 1.17.1-1ubuntu0.1 | hirsute | ||
Affected | pkg:deb/ubuntu/libc-ares-dev?distro=focal | ubuntu | libc-ares-dev | < 1.15.0-1ubuntu0.1 | focal | ||
Affected | pkg:deb/ubuntu/libc-ares-dev?distro=bionic | ubuntu | libc-ares-dev | < 1.14.0-1ubuntu0.1 | bionic |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |