Logo
vulnerabilityCVE-2023-32067
Name
CVE-2023-32067
Source
NVD ( link)Debian ( link)
Description
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
c-ares
Patched

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.34.6
Not Affected
buildroot
master
1.34.6
Not Affected
yocto
master
1.34.6
Not Affected
yocto
scarthgap
1.27.0
Not Affected

Resolved with patches#


c-ares (yocto:kirkstone)

#
Title
Author
Resolve
1
Merge pull request from GHSA-9g78-jv2r-p7vc
Brad House <brad@brad-house.com>
CVE-2023-32067