CVE-2022-4904
published 2023-03-06CVE-2022-4904: A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary…
high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| c-ares | c-ares | >= 0 < 1.17.1-1+deb11u2 | 1.17.1-1+deb11u2 |
| c-ares | c-ares | >= 0 < 1.18.1-2 | 1.18.1-2 |
| c-ares | c-ares | >= 0 < 1.18.1-2 | 1.18.1-2 |
| c-ares | c-ares | >= 0 < 1.18.1-2 | 1.18.1-2 |
| c-ares_project | c-ares | < 1.19.0 | 1.19.0 |
| c-ares_project | c-ares | — | — |
| debian | c-ares | < c-ares 1.18.1-2 (bookworm) | c-ares 1.18.1-2 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | azl3_grpc_1.42.0-7_on_azure_linux_3.0 | — | — |
| msrc | azl3_grpc_1.62.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_c-ares_1.19.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_grpc_1.42.0-11_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nodejs_16.20.1-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python-gevent_21.1.2-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_rubygem-mini_portile2_2.8.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_c-ares_1.19.0-1_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_grpc_1.35.0-9_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
osv8.6HIGH
GHSA
GHSA-v7h6-g695-5j7q: A flaw was found in the c-ares package
ghsa_unreviewed·2023-03-07
CVE-2022-4904 [HIGH] CWE-119 GHSA-v7h6-g695-5j7q: A flaw was found in the c-ares package
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
OSV
CVE-2022-4904: A flaw was found in the c-ares package
osv·2023-03-06·CVSS 8.6
CVE-2022-4904 [HIGH] CVE-2022-4904: A flaw was found in the c-ares package
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Microsoft
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string which allows a possible arbitrary length stack overflow. This issue may cause a d
vendor_msrc·2023-03-14·CVSS 8.6
CVE-2022-4904 [HIGH] CWE-1284 A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string which allows a possible arbitrary length stack overflow. This issue may cause a d
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more informati
Ubuntu
c-ares vulnerability
vendor_ubuntu·2023-03-02
CVE-2022-4904 c-ares vulnerability
Title: c-ares vulnerability
Summary: c-ares could be made to crash or run programs if it processed specially
crafted input.
It was discovered that c-ares incorrectly handled certain sortlist strings.
A remote attacker could use this issue to cause c-ares to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
c-ares: buffer overflow in config_sortlist() due to missing string length check
vendor_redhat·2022-12-13·CVSS 8.6
CVE-2022-4904 [HIGH] CWE-20 c-ares: buffer overflow in config_sortlist() due to missing string length check
c-ares: buffer overflow in config_sortlist() due to missing string length check
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
Statement: The severity of this vulnerability is not important but moderate because exploiting the vulnerability can lead to a disruption of the availability of an applicati
Debian
CVE-2022-4904: c-ares - A flaw was found in the c-ares package. The ares_set_sortlist is missing checks ...
vendor_debian·2022·CVSS 8.6
CVE-2022-4904 [HIGH] CVE-2022-4904: c-ares - A flaw was found in the c-ares package. The ares_set_sortlist is missing checks ...
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
Scope: local
bookworm: resolved (fixed in 1.18.1-2)
bullseye: resolved (fixed in 1.17.1-1+deb11u2)
forky: resolved (fixed in 1.18.1-2)
sid: resolved (fixed in 1.18.1-2)
trixie: resolved (fixed in 1.18.1-2)
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2168631https://github.com/c-ares/c-ares/issues/496https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33LDNS6RPOPP36Z4MPWXALUQZXJCWJS2/https://security.gentoo.org/glsa/202401-02https://bugzilla.redhat.com/show_bug.cgi?id=2168631https://github.com/c-ares/c-ares/issues/496https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33LDNS6RPOPP36Z4MPWXALUQZXJCWJS2/https://security.gentoo.org/glsa/202401-02
2023-03-06
Published