Total vulnerabilities in the database
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.
Software | From | Fixed in |
---|---|---|
c-ares_project / c-ares | - | 1.19.1 |
fedoraproject / fedora | 37 | 37.x |
fedoraproject / fedora | 38 | 38.x |
debian / debian_linux | 10.0 | 10.0.x |
debian / debian_linux | 11.0 | 11.0.x |