UbuntuUpdates.org

Package "c-ares"

Name: c-ares

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • asynchronous name resolver - development files
  • asynchronous name resolver

Latest version: 1.18.1-2ubuntu0.1
Release: lunar (23.04)
Level: updates
Repository: main

Links



Other versions of "c-ares" in Lunar

Repository Area Version
base main 1.18.1-2
security main 1.18.1-2ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.18.1-2ubuntu0.1 2023-06-14 16:07:08 UTC

  c-ares (1.18.1-2ubuntu0.1) lunar-security; urgency=medium

  * SECURITY UPDATE: buffer underflow on certain ipv6 addresses
    - debian/patches/CVE-2023-31130.diff: add newer inet_net_pton_ipv6()
      and fix test cases in src/lib/inet_net_pton.c,
      test/ares-test-internal.cc.
    - CVE-2023-31130
  * SECURITY UPDATE: denial of service via 0-byte UDP payload
    - debian/patches/CVE-2023-32067.diff: check length in
      src/lib/ares_process.c.
    - CVE-2023-32067

 -- Marc Deslauriers <email address hidden> Mon, 12 Jun 2023 14:39:02 -0400

CVE-2023-32067 c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malf



About   -   Send Feedback to @ubuntu_updates