Opened 11 months ago

Closed 11 months ago

Last modified 9 months ago

#18077 closed enhancement (fixed)

c-ares-1.19.1

Reported by: Douglas R. Reno Owned by: ken@…
Priority: elevated Milestone: 12.0
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version

Change History (5)

comment:1 by ken@…, 11 months ago

Priority: normalelevated

From https://c-ares.org/vulns.html

CVE-2023-32067 - May 22 2023

High. 0-byte UDP payload causes Denial of Service. Fixed in 1.19.1. CVE-2023-32067

CVE-2023-31147 - May 22 2023

Moderate. Insufficient randomness in generation of DNS query IDs. Fixed in 1.19.1. CVE-2023-31147

CVE-2023-31130 - May 22 2023

Moderate. Buffer Underwrite in ares_inet_net_pton(). Fixed in 1.19.1. CVE-2023-31130

CVE-2023-31124 - May 22 2023

Low. AutoTools does not set CARES_RANDOM_FILE during cross compilation. Fixed in 1.19.1. CVE-2023-31124

Obviously, BLFS does not support cross-compilation nor use autotools for this package.

comment:2 by ken@…, 11 months ago

Owner: changed from blfs-book to ken@…

comment:3 by ken@…, 11 months ago

Fined in 05e1c8cc07 11.3-548

comment:4 by ken@…, 11 months ago

Resolution: fixed
Status: newclosed

Security Advisory SA 11.3-028.

comment:5 by Bruce Dubbs, 9 months ago

Milestone: 11.412.0

Milestone renamed

Note: See TracTickets for help on using tickets.