CVE-2023-32067
published 2023-05-25CVE-2023-32067: c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.58%
72.7th percentile
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| c-ares | c-ares | < 1.19.1 | 1.19.1 |
| c-ares | c-ares | >= 0 < 1.17.1-1+deb11u3 | 1.17.1-1+deb11u3 |
| c-ares | c-ares | >= 0 < 1.18.1-3 | 1.18.1-3 |
| c-ares | c-ares | >= 0 < 1.18.1-3 | 1.18.1-3 |
| c-ares | c-ares | >= 0 < 1.18.1-3 | 1.18.1-3 |
| c-ares | c-ares | >= 0 < 1.15.0-1ubuntu0.3 | 1.15.0-1ubuntu0.3 |
| c-ares | c-ares | >= 0 < 1.18.1-1ubuntu0.22.04.2 | 1.18.1-1ubuntu0.22.04.2 |
| c-ares | c-ares | >= 0 < 1.10.0-3ubuntu0.2+esm2 | 1.10.0-3ubuntu0.2+esm2 |
| c-ares | c-ares | >= 0 < 1.14.0-1ubuntu0.2+esm1 | 1.14.0-1ubuntu0.2+esm1 |
| c-ares_project | c-ares | < 1.19.1 | 1.19.1 |
| debian | c-ares | < c-ares 1.18.1-3 (bookworm) | c-ares 1.18.1-3 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_grpc_1.42.0-7_on_azure_linux_3.0 | — | — |
| msrc | azl3_grpc_1.62.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_c-ares_1.19.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_fluent-bit_2.1.10-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_grpc_1.42.0-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nodejs18_18.17.1-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-02-15
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-15
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, Use After Free, NULL Pointer Dereference, Improper Input Validation, Missing Encryption of Sensitive Data, Allocation of Resources Wit
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
c-ares vulnerabilities
vendor_ubuntu·2023-09-11·CVSS 4.1
CVE-2023-32067 [MEDIUM] c-ares vulnerabilities
Title: c-ares vulnerabilities
Summary: Several security issues were fixed in c-ares.
USN-6164-1 fixed several vulnerabilities in c-ares. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Hannes Moesl discovered that c-ares incorrectly handled certain ipv6
addresses. An attacker could use this issue to cause c-ares to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-31130)
Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A
remote attacker could possibly use this issue to cause c-res to crash,
resulting in a denial of service. (CVE-2023-32067)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
c-ares vulnerabilities
vendor_ubuntu·2023-06-14·CVSS 4.1
CVE-2023-31130 [MEDIUM] c-ares vulnerabilities
Title: c-ares vulnerabilities
Summary: Several security issues were fixed in c-ares.
Hannes Moesl discovered that c-ares incorrectly handled certain ipv6
addresses. An attacker could use this issue to cause c-ares to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-31130)
Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A
remote attacker could possibly use this issue to cause c-res to crash,
resulting in a denial of service. (CVE-2023-32067)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
c-ares: 0-byte UDP payload Denial of Service
vendor_redhat·2023-05-22·CVSS 7.5
CVE-2023-32067 [HIGH] CWE-400 c-ares: 0-byte UDP payload Denial of Service
c-ares: 0-byte UDP payload Denial of Service
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.
A vulnerability was found in c-ares. This issue occurs due to a 0-byte UDP payload that can cause a Denial of Service.
Package: c-ares (Red Hat Enterprise Linux 6) - Out of support scope
Microsoft
0-byte UDP payload DoS in c-ares
vendor_msrc·2023-05-09·CVSS 7.5
CVE-2023-32067 [HIGH] CWE-400 0-byte UDP payload DoS in c-ares
0-byte UDP payload DoS in c-ares
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en
Debian
CVE-2023-32067: c-ares - c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of se...
vendor_debian·2023·CVSS 7.5
CVE-2023-32067 [HIGH] CVE-2023-32067: c-ares - c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of se...
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.
Scope: local
bookworm: resolved (fixed in 1.18.1-3)
bullseye: resolved (fixed in 1.17.1-1+deb11u3)
forky: resolved (fixed in 1.18.1-3)
sid: resolved (fixed in 1.18.1-3)
trixie: resolved (fixed in 1.18.1-3)
OSV
c-ares vulnerabilities
osv·2023-09-11·CVSS 6.4
CVE-2023-31130 [MEDIUM] c-ares vulnerabilities
c-ares vulnerabilities
USN-6164-1 fixed several vulnerabilities in c-ares. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Hannes Moesl discovered that c-ares incorrectly handled certain ipv6
addresses. An attacker could use this issue to cause c-ares to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-31130)
Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A
remote attacker could possibly use this issue to cause c-res to crash,
resulting in a denial of service. (CVE-2023-32067)
OSV
c-ares vulnerabilities
osv·2023-06-14·CVSS 6.4
CVE-2023-31130 [MEDIUM] c-ares vulnerabilities
c-ares vulnerabilities
Hannes Moesl discovered that c-ares incorrectly handled certain ipv6
addresses. An attacker could use this issue to cause c-ares to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-31130)
Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A
remote attacker could possibly use this issue to cause c-res to crash,
resulting in a denial of service. (CVE-2023-32067)
OSV
CVE-2023-32067: c-ares is an asynchronous resolver library
osv·2023-05-25·CVSS 7.5
CVE-2023-32067 [HIGH] CVE-2023-32067: c-ares is an asynchronous resolver library
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/c-ares/c-ares/releases/tag/cares-1_19_1https://github.com/c-ares/c-ares/security/advisories/GHSA-9g78-jv2r-p7vchttps://lists.debian.org/debian-lts-announce/2023/06/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/B5Z5XFNXTNPTCBBVXFDNZQVLLIE6VRBY/https://lists.fedoraproject.org/archives/list/[email protected]/message/UBFWILTA33LOSV23P44FGTQQIDRJHIY7/https://security.gentoo.org/glsa/202310-09https://security.netapp.com/advisory/ntap-20240605-0004/https://www.debian.org/security/2023/dsa-5419https://github.com/c-ares/c-ares/releases/tag/cares-1_19_1https://github.com/c-ares/c-ares/security/advisories/GHSA-9g78-jv2r-p7vchttps://lists.debian.org/debian-lts-announce/2023/06/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/B5Z5XFNXTNPTCBBVXFDNZQVLLIE6VRBY/https://lists.fedoraproject.org/archives/list/[email protected]/message/UBFWILTA33LOSV23P44FGTQQIDRJHIY7/https://security.gentoo.org/glsa/202310-09https://security.netapp.com/advisory/ntap-20240605-0004/https://www.debian.org/security/2023/dsa-5419
2023-05-25
Published