cbcvebase.
CVE-2016-5180
published 2016-10-03

CVE-2016-5180: Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds…

PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
8.58%
94.5th percentile
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares
c-aresc-ares>= 0 < 1.12.0-11.12.0-1
c-aresc-ares>= 0 < 1.12.0-11.12.0-1

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: a hostname with an escaped trailing dot (e.g., 'hello\.') causes ares_create_query to miscalculate buffer size, writing one byte beyond the end of a heap buffer. Any DNS query input containing an escaped trailing dot should be treated as suspicious.
  • The vulnerable function is ares_create_query in c-ares 1.x before 1.12.0. Monitor or audit calls to this function when processing attacker-controlled hostnames.
  • ·Affected versions are c-ares 1.x before 1.12.0. Packages on RHEL 5, 6, and 7 (c-ares) and Red Hat Software Collections (nodejs010-c-ares, nodejs010-nodejs) are listed as 'Will not fix', meaning patched packages may not be available from the vendor for those platforms.
  • ·Debian fixed the vulnerability in package version 1.12.0-1 across all active releases (bookworm, bullseye, forky, sid, trixie). Confirm installed c-ares version is >= 1.12.0-1 on Debian-based systems.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8MEDIUM
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.