cbcvebase.
CVE-2024-25629
published 2024-02-23

CVE-2024-25629: c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.35%
27.1th percentile
c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
c-aresc-ares< 1.27.01.27.0
c-aresc-ares>= 0 < 1.27.0-11.27.0-1
c-aresc-ares>= 0 < 1.27.0-11.27.0-1
debianc-ares< c-ares 1.27.0-1 (forky)c-ares 1.27.0-1 (forky)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_c-ares_1.25.0-1
msrcazl3_c-ares_1.30.0-1
msrcazl3_ceph_18.2.2-1
msrcazl3_ceph_18.2.2-8
msrcazl3_fluent-bit_3.0.6-1
msrcazl3_fluent-bit_3.0.6-2
msrcazl3_grpc_1.62.3-1
msrcazl3_nodejs_20.10.0-2
msrcazl3_nodejs_20.14.0-1
msrcazl3_python-gevent_23.9.1-4
msrcazl3_rubygem-mini_portile2_2.8.4-1
msrcazl3_tensorflow_2.16.1-9
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_c-ares_1.19.1-2
msrccbl2_ceph_16.2.10-7
msrccbl2_fluent-bit_2.2.3-1
msrccbl2_fluent-bit_3.0.6-2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.