A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service that uses c-ares lib. The highest threat from this vulnerability is to this service availability.
2021-05-13T14:15:17.503
2024-11-21T05:03:04.703
Modified
CVSSv3.1: 3.3 (LOW)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | c-ares | c-ares | 1.16.0 | Yes |
| Operating System | fedoraproject | fedora | 33 | Yes |