A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
2023-03-06T23:15:11.390
2024-11-21T07:36:12.953
Modified
CVSSv3.1: 8.6 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | c-ares_project | c-ares | < 1.19.0 | Yes |
Application | redhat | software_collections | - | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | redhat | enterprise_linux | 9.0 | Yes |
Operating System | fedoraproject | fedora | 36 | Yes |