Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-3672


A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.


Published

2021-11-23T19:15:07.877

Last Modified

2024-11-21T06:22:07.650

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.6 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application c-ares_project c-ares < 1.17.2 Yes
Operating System fedoraproject fedora 33 Yes
Operating System fedoraproject fedora 34 Yes
Operating System redhat enterprise_linux 7.0 Yes
Operating System redhat enterprise_linux 7.7 Yes
Operating System redhat enterprise_linux 8.0 Yes
Operating System redhat enterprise_linux_computer_node 1 Yes
Operating System redhat enterprise_linux_eus 7.7 Yes
Operating System redhat enterprise_linux_eus 8.1 Yes
Operating System redhat enterprise_linux_eus 8.2 Yes
Operating System redhat enterprise_linux_eus 8.4 Yes
Operating System redhat enterprise_linux_for_ibm_z_systems 8.0 Yes
Operating System redhat enterprise_linux_for_ibm_z_systems_eus 8.1 Yes
Operating System redhat enterprise_linux_for_ibm_z_systems_eus 8.2 Yes
Operating System redhat enterprise_linux_for_ibm_z_systems_eus 8.4 Yes
Operating System redhat enterprise_linux_for_power_little_endian 8.0 Yes
Operating System redhat enterprise_linux_for_power_little_endian_eus 8.1 Yes
Operating System redhat enterprise_linux_for_power_little_endian_eus 8.2 Yes
Operating System redhat enterprise_linux_for_power_little_endian_eus 8.4 Yes
Operating System redhat enterprise_linux_server_aus 8.2 Yes
Operating System redhat enterprise_linux_server_aus 8.4 Yes
Operating System redhat enterprise_linux_server_tus 8.2 Yes
Operating System redhat enterprise_linux_server_tus 8.4 Yes
Operating System redhat enterprise_linux_server_update_services_for_sap_solutions 8.1 Yes
Operating System redhat enterprise_linux_server_update_services_for_sap_solutions 8.2 Yes
Operating System redhat enterprise_linux_server_update_services_for_sap_solutions 8.4 Yes
Operating System redhat enterprise_linux_tus 8.4 Yes
Operating System redhat enterprise_linux_workstation 1 Yes
Application siemens sinec_infrastructure_network_services < 1.0.1.1 Yes
Application nodejs node.js ≤ 12.12.0 Yes
Application nodejs node.js < 12.22.5 Yes
Application nodejs node.js ≤ 14.14.0 Yes
Application nodejs node.js < 14.17.5 Yes
Application nodejs node.js < 16.6.2 Yes
Application pgbouncer pgbouncer ≤ 1.17.0 Yes

References