CVE-2021-3672
published 2021-11-23CVE-2021-3672: A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong…
PriorityP432medium5.6CVSS 3.1
AVNACHPRNUINSUCLILAL
EPSS
2.62%
83.7th percentile
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| c-ares | c-ares | >= 0 < 1.17.1-1+deb11u1 | 1.17.1-1+deb11u1 |
| c-ares | c-ares | >= 0 < 1.17.1-1.1 | 1.17.1-1.1 |
| c-ares | c-ares | >= 0 < 1.17.1-1.1 | 1.17.1-1.1 |
| c-ares | c-ares | >= 0 < 1.17.1-1.1 | 1.17.1-1.1 |
| c-ares_project | c-ares | — | — |
| c-ares_project | c-ares | >= 1.0.0 < 1.17.2 | 1.17.2 |
| debian | c-ares | < c-ares 1.17.1-1.1 (bookworm) | c-ares 1.17.1-1.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_ceph_18.2.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.2-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_ceph_16.2.10-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pgbouncer_1.16.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_c-ares_1.18.1-1_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_pgbouncer_1.16.1-1_on_cbl_mariner_1.0 | — | — |
| nodejs | node.js | 12.0.0 – 12.12.0 | — |
| nodejs | node.js | >= 12.13.0 < 12.22.5 | 12.22.5 |
| nodejs | node.js | 14.0.0 – 14.14.0 | — |
| nodejs | node.js | >= 14.15.0 < 14.17.5 | 14.17.5 |
| nodejs | node.js | >= 16.0.0 < 16.6.2 | 16.6.2 |
| paloalto | pan-os | — | — |
| pgbouncer | pgbouncer | <= 1.17.0 | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa5.6MEDIUM
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_msrc5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Microsoft
A flaw was found in c-ares library where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Doma
vendor_msrc·2021-11-09·CVSS 5.6
CVE-2021-3672 [MEDIUM] CWE-79 A flaw was found in c-ares library where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Doma
A flaw was found in c-ares library where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX
Ubuntu
c-ares vulnerability
vendor_ubuntu·2021-08-10
CVE-2021-3672 c-ares vulnerability
Title: c-ares vulnerability
Summary: c-ares could be made to return wrong domains.
Philipp Jeitner and Haya Shulman discovered that c-ares incorrectly
validated certain hostnames returned by DNS servers. A remote attacker
could possibly use this issue to perform Domain Hijacking attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
c-ares: Missing input validation of host names may lead to domain hijacking
vendor_redhat·2021-08-10·CVSS 5.6
CVE-2021-3672 [MEDIUM] CWE-79 c-ares: Missing input validation of host names may lead to domain hijacking
c-ares: Missing input validation of host names may lead to domain hijacking
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
Package: c-ares (Red Hat Enterprise Linux 6) - Out of support scope
Ubuntu
c-ares vulnerability
vendor_ubuntu·2021-08-10
CVE-2021-3672 c-ares vulnerability
Title: c-ares vulnerability
Summary: c-ares could be made to return wrong domains.
USN-5034-1 fixed a vulnerability in c-ares. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Philipp Jeitner and Haya Shulman discovered that c-ares incorrectly
validated certain hostnames returned by DNS servers. A remote attacker
could possibly use this issue to perform Domain Hijacking attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-3672: c-ares - A flaw was found in c-ares library, where a missing input validation check of ho...
vendor_debian·2021·CVSS 5.6
CVE-2021-3672 [MEDIUM] CVE-2021-3672: c-ares - A flaw was found in c-ares library, where a missing input validation check of ho...
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 1.17.1-1.1)
bullseye: resolved (fixed in 1.17.1-1+deb11u1)
forky: resolved (fixed in 1.17.1-1.1)
sid: resolved (fixed in 1.17.1-1.1)
trixie: resolved (fixed in 1.17.1-1.1)
OSV
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in pycares
osv·2022-07-05·CVSS 5.6
CVE-2021-3672 [MEDIUM] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in pycares
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in pycares
### Impact
pycares versions < 4.2.0 are affected by [CVE-2021-3672](https://nvd.nist.gov/vuln/detail/CVE-2021-3672).
### Patches
Update to version 4.2.0.
GHSA
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in pycares
ghsa·2022-07-05·CVSS 5.6
CVE-2021-3672 [MEDIUM] CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in pycares
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in pycares
### Impact
pycares versions < 4.2.0 are affected by [CVE-2021-3672](https://nvd.nist.gov/vuln/detail/CVE-2021-3672).
### Patches
Update to version 4.2.0.
GHSA
GHSA-hghm-3vc3-hppj: A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of w
ghsa_unreviewed·2022-05-24
CVE-2021-3672 [HIGH] CWE-79 GHSA-hghm-3vc3-hppj: A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of w
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
OSV
CVE-2021-3672: A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of w
osv·2021-11-23·CVSS 5.6
CVE-2021-3672 [MEDIUM] CVE-2021-3672: A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of w
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1988342https://c-ares.haxx.se/adv_20210810.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://security.gentoo.org/glsa/202401-02https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1988342https://c-ares.haxx.se/adv_20210810.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://security.gentoo.org/glsa/202401-02https://www.oracle.com/security-alerts/cpujul2022.html
2021-11-23
Published