[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3682-1 c-ares -- c-ares

ID: oval:org.secpod.oval:def:602633Date: (C)2016-10-04   (M)2023-12-20
Class: PATCHFamily: unix




Gzob Qq discovered that the query-building functions in c-ares, an asynchronous DNS request library would not correctly process crafted query names, resulting in a heap buffer overflow and potentially leading to arbitrary code execution.

Platform:
Debian 8.x
Product:
libc-ares2
Reference:
DSA-3682-1
CVE-2016-5180
CVE    1
CVE-2016-5180
CPE    3
cpe:/o:debian:debian_linux:8.x
cpe:/a:haxx:libc-ares2
cpe:/o:debian:debian_linux:8.0

© SecPod Technologies