Logo
vulnerabilityCVE-2023-31130
Name
CVE-2023-31130
Source
NVD ( link)Debian ( link)
Description
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an address via ares_set_sortlist(). However, users may externally use ares_inet_net_pton() for other purposes and thus be vulnerable to more severe issues. This issue has been fixed in 1.19.1.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
c-ares
Patched

Vulnerability Ratings#


4.1
CVSSv31
6.4
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.34.6
Not Affected
buildroot
master
1.34.6
Not Affected
yocto
master
1.34.6
Not Affected
yocto
scarthgap
1.27.0
Not Affected

Resolved with patches#


c-ares (yocto:kirkstone)

#
Title
Author
Resolve
1
Merge pull request from GHSA-x6mf-cxr9-8q6v
Brad House <brad@brad-house.com>
CVE-2023-31130