CVE-2023-31130
MEDIUMc-ares < 1.19.1 - Out-of-bounds Write via ares_inet_net_pton
Title source: llmDescription
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an address via ares_set_sortlist(). However, users may externally use ares_inet_net_pton() for other purposes and thus be vulnerable to more severe issues. This issue has been fixed in 1.19.1.
References (8)
Core 8
Core References
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/B5Z5XFNXTNPTCBBVXFDNZQVLLIE6VRBY/
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/UBFWILTA33LOSV23P44FGTQQIDRJHIY7/
Third Party Advisory
https://security.gentoo.org/glsa/202310-09
Third Party Advisory
https://www.debian.org/security/2023/dsa-5419
Vendor Advisory
https://security.netapp.com/advisory/ntap-20240605-0005/
Third Party Advisory x_refsource_confirm
https://github.com/c-ares/c-ares/security/advisories/GHSA-x6mf-cxr9-8q6v
Release Notes x_refsource_misc
https://github.com/c-ares/c-ares/releases/tag/cares-1_19_1
Scores
CVSS v3
4.1
EPSS
0.0001
EPSS Percentile
1.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-787
CWE-124
Status
published
Products (5)
c-ares_project/c-ares
< 1.19.1
debian/debian_linux
10.0
debian/debian_linux
11.0
fedoraproject/fedora
37
fedoraproject/fedora
38
Published
May 25, 2023
Tracked Since
Feb 18, 2026