CVE-2023-31130
published 2023-05-25CVE-2023-31130: c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2"…
PriorityP427medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
0.33%
25.5th percentile
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an address via ares_set_sortlist(). However, users may externally use ares_inet_net_pton() for other purposes and thus be vulnerable to more severe issues. This issue has been fixed in 1.19.1.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| c-ares | c-ares | < 1.19.1 | 1.19.1 |
| c-ares | c-ares | >= 0 < 1.17.1-1+deb11u3 | 1.17.1-1+deb11u3 |
| c-ares | c-ares | >= 0 < 1.18.1-3 | 1.18.1-3 |
| c-ares | c-ares | >= 0 < 1.18.1-3 | 1.18.1-3 |
| c-ares | c-ares | >= 0 < 1.18.1-3 | 1.18.1-3 |
| c-ares | c-ares | >= 0 < 1.15.0-1ubuntu0.3 | 1.15.0-1ubuntu0.3 |
| c-ares | c-ares | >= 0 < 1.18.1-1ubuntu0.22.04.2 | 1.18.1-1ubuntu0.22.04.2 |
| c-ares | c-ares | >= 0 < 1.10.0-3ubuntu0.2+esm2 | 1.10.0-3ubuntu0.2+esm2 |
| c-ares | c-ares | >= 0 < 1.14.0-1ubuntu0.2+esm1 | 1.14.0-1ubuntu0.2+esm1 |
| c-ares_project | c-ares | < 1.19.1 | 1.19.1 |
| debian | c-ares | < c-ares 1.18.1-3 (bookworm) | c-ares 1.18.1-3 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_ceph_18.2.2-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_grpc_1.42.0-7_on_azure_linux_3.0 | — | — |
| msrc | azl3_grpc_1.62.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_c-ares_1.19.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_ceph_16.2.10-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_fluent-bit_2.1.10-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_grpc_1.42.0-11_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nodejs18_18.17.1-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.4MEDIUM
vendor_msrc6.4MEDIUM
vendor_debian4.1MEDIUM
vendor_redhat4.1MEDIUM
vendor_ubuntu4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-02-15
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-15
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, Use After Free, NULL Pointer Dereference, Improper Input Validation, Missing Encryption of Sensitive Data, Allocation of Resources Wit
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
c-ares vulnerabilities
vendor_ubuntu·2023-09-11·CVSS 4.1
CVE-2023-32067 [MEDIUM] c-ares vulnerabilities
Title: c-ares vulnerabilities
Summary: Several security issues were fixed in c-ares.
USN-6164-1 fixed several vulnerabilities in c-ares. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Hannes Moesl discovered that c-ares incorrectly handled certain ipv6
addresses. An attacker could use this issue to cause c-ares to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-31130)
Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A
remote attacker could possibly use this issue to cause c-res to crash,
resulting in a denial of service. (CVE-2023-32067)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
c-ares vulnerabilities
vendor_ubuntu·2023-06-14·CVSS 4.1
CVE-2023-31130 [MEDIUM] c-ares vulnerabilities
Title: c-ares vulnerabilities
Summary: Several security issues were fixed in c-ares.
Hannes Moesl discovered that c-ares incorrectly handled certain ipv6
addresses. An attacker could use this issue to cause c-ares to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-31130)
Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A
remote attacker could possibly use this issue to cause c-res to crash,
resulting in a denial of service. (CVE-2023-32067)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
c-ares: Buffer Underwrite in ares_inet_net_pton()
vendor_redhat·2023-05-22·CVSS 4.1
CVE-2023-31130 [MEDIUM] c-ares: Buffer Underwrite in ares_inet_net_pton()
c-ares: Buffer Underwrite in ares_inet_net_pton()
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an address via ares_set_sortlist(). However, users may externally use ares_inet_net_pton() for other purposes and thus be vulnerable to more severe issues. This issue has been fixed in 1.19.1.
A vulnerability was found in c-ares. This issue occurs in the ares_inet_net_pton() function, which is vulnerable to a buffer underflow for certain ipv6 addresses. "0::00:00:00/2" in particular was found to cause an issue. C-ares only uses this
Microsoft
Buffer Underwrite in ares_inet_net_pton()
vendor_msrc·2023-05-09·CVSS 6.4
CVE-2023-31130 [MEDIUM] CWE-787 Buffer Underwrite in ares_inet_net_pton()
Buffer Underwrite in ares_inet_net_pton()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microso
Debian
CVE-2023-31130: c-ares - c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable t...
vendor_debian·2023·CVSS 4.1
CVE-2023-31130 [MEDIUM] CVE-2023-31130: c-ares - c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable t...
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an address via ares_set_sortlist(). However, users may externally use ares_inet_net_pton() for other purposes and thus be vulnerable to more severe issues. This issue has been fixed in 1.19.1.
Scope: local
bookworm: resolved (fixed in 1.18.1-3)
bullseye: resolved (fixed in 1.17.1-1+deb11u3)
forky: resolved (fixed in 1.18.1-3)
sid: resolved (fixed in 1.18.1-3)
trixie: resolved (fixed in 1.18.1-3)
OSV
c-ares vulnerabilities
osv·2023-09-11·CVSS 6.4
CVE-2023-31130 [MEDIUM] c-ares vulnerabilities
c-ares vulnerabilities
USN-6164-1 fixed several vulnerabilities in c-ares. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Hannes Moesl discovered that c-ares incorrectly handled certain ipv6
addresses. An attacker could use this issue to cause c-ares to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-31130)
Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A
remote attacker could possibly use this issue to cause c-res to crash,
resulting in a denial of service. (CVE-2023-32067)
OSV
c-ares vulnerabilities
osv·2023-06-14·CVSS 6.4
CVE-2023-31130 [MEDIUM] c-ares vulnerabilities
c-ares vulnerabilities
Hannes Moesl discovered that c-ares incorrectly handled certain ipv6
addresses. An attacker could use this issue to cause c-ares to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-31130)
Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A
remote attacker could possibly use this issue to cause c-res to crash,
resulting in a denial of service. (CVE-2023-32067)
OSV
CVE-2023-31130: c-ares is an asynchronous resolver library
osv·2023-05-25·CVSS 6.4
CVE-2023-31130 [MEDIUM] CVE-2023-31130: c-ares is an asynchronous resolver library
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an address via ares_set_sortlist(). However, users may externally use ares_inet_net_pton() for other purposes and thus be vulnerable to more severe issues. This issue has been fixed in 1.19.1.
No detection rules found.
No public exploits indexed.
https://github.com/c-ares/c-ares/releases/tag/cares-1_19_1https://github.com/c-ares/c-ares/security/advisories/GHSA-x6mf-cxr9-8q6vhttps://lists.debian.org/debian-lts-announce/2023/06/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/B5Z5XFNXTNPTCBBVXFDNZQVLLIE6VRBY/https://lists.fedoraproject.org/archives/list/[email protected]/message/UBFWILTA33LOSV23P44FGTQQIDRJHIY7/https://security.gentoo.org/glsa/202310-09https://security.netapp.com/advisory/ntap-20240605-0005/https://www.debian.org/security/2023/dsa-5419https://github.com/c-ares/c-ares/releases/tag/cares-1_19_1https://github.com/c-ares/c-ares/security/advisories/GHSA-x6mf-cxr9-8q6vhttps://lists.debian.org/debian-lts-announce/2023/06/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/B5Z5XFNXTNPTCBBVXFDNZQVLLIE6VRBY/https://lists.fedoraproject.org/archives/list/[email protected]/message/UBFWILTA33LOSV23P44FGTQQIDRJHIY7/https://security.gentoo.org/glsa/202310-09https://security.netapp.com/advisory/ntap-20240605-0005/https://www.debian.org/security/2023/dsa-5419
2023-05-25
Published