cbcvebase.
CVE-2023-31147
published 2023-05-25

CVE-2023-31147: c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS…

PriorityP432medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.91%
55.8th percentile
c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so will generate predictable output. Input from the random number generator is fed into a non-compilant RC4 implementation and may not be as strong as the original RC4 implementation. No attempt is made to look for modern OS-provided CSPRNGs like arc4random() that is widely available. This issue has been fixed in version 1.19.1.

Affected

21 ranges
VendorProductVersion rangeFixed in
c-aresc-ares< 1.19.11.19.1
c-aresc-ares>= 0 < 1.19.1-21.19.1-2
c-aresc-ares>= 0 < 1.19.1-21.19.1-2
c-ares_projectc-ares< 1.19.11.19.1
debianc-ares< c-ares 1.19.1-2 (forky)c-ares 1.19.1-2 (forky)
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_ceph_18.2.2-8_on_azure_linux_3.0
msrcazl3_grpc_1.42.0-7_on_azure_linux_3.0
msrcazl3_grpc_1.62.0-2_on_azure_linux_3.0
msrcazl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-9_on_azure_linux_3.0
msrccbl2_c-ares_1.19.1-1_on_cbl_mariner_2.0
msrccbl2_ceph_16.2.10-7_on_cbl_mariner_2.0
msrccbl2_fluent-bit_2.1.10-1_on_cbl_mariner_2.0
msrccbl2_grpc_1.42.0-10_on_cbl_mariner_2.0
msrccbl2_nodejs18_18.17.1-2_on_cbl_mariner_2.0
msrccbl2_nodejs_16.20.1-2_on_cbl_mariner_2.0
msrccbl2_python-gevent_21.1.2-3_on_cbl_mariner_2.0
msrccm1_c-ares_1.19.1-1_on_cbl_mariner_1.0
paloaltopan-os

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian5.9LOW
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.