c-ares: NAPTR parser out of bounds access
Published Jul 7, 2017
7.5
HIGHCVSS 3.1
EPSS 3.31%
Description
The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.
Affected products
No data.
Configuration 1
Configuration 2
- ≥ 4.0.0 · ≤ 4.1.2
- ≥ 4.2.0 · < 4.8.4
- ≥ 5.0.0 · ≤ 5.12.0
- ≥ 6.0.0 · ≤ 6.8.1
- ≥ 6.9.0 · < 6.11.1
- ≥ 7.0.0 · < 7.10.1
- ≥ 8.0.0 · < 8.1.4
No data.
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-nodejs6-nodejs-0:6.11.3-2.el6
Fixed · RHSA-2017:2908
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-nodejs6-nodejs-0:6.11.3-2.el6
Fixed · RHSA-2017:2908
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs6-nodejs-0:6.11.3-2.el7
Fixed · RHSA-2017:2908
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-nodejs6-nodejs-0:6.11.3-2.el7
Fixed · RHSA-2017:2908
Red Hat Enterprise Linux 5
c-ares
Will not fix
Red Hat Enterprise Linux 6
c-ares
Will not fix
Red Hat Enterprise Linux 7
c-ares
Will not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools
nodejs
Will not fix
Red Hat OpenShift Enterprise 2
nodejs010-nodejs
Will not fix
Red Hat OpenShift Enterprise 3
nodejs
Will not fix
Red Hat Software Collections
nodejs010-c-ares
Will not fix
Red Hat Software Collections
nodejs010-nodejs
Not affected
Red Hat Software Collections
rh-nodejs4-nodejs
Will not fix
Red Hat Software Collections
rh-nodejs6-nodejs
Affected
Red Hat Software Collections
rh-nodejs8-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-nodejs6-nodejs-0:6.11.3-2.el6 | Fixed | RHSA-2017:2908 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-nodejs6-nodejs-0:6.11.3-2.el6 | Fixed | RHSA-2017:2908 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs6-nodejs-0:6.11.3-2.el7 | Fixed | RHSA-2017:2908 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-nodejs6-nodejs-0:6.11.3-2.el7 | Fixed | RHSA-2017:2908 |
| Red Hat Enterprise Linux 5 | c-ares | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | c-ares | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | c-ares | Will not fix | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | nodejs | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | nodejs010-nodejs | Will not fix | n/a |
| Red Hat OpenShift Enterprise 3 | nodejs | Will not fix | n/a |
| Red Hat Software Collections | nodejs010-c-ares | Will not fix | n/a |
| Red Hat Software Collections | nodejs010-nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs4-nodejs | Will not fix | n/a |
| Red Hat Software Collections | rh-nodejs6-nodejs | Affected | n/a |
| Red Hat Software Collections | rh-nodejs8-nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- http://www.securityfocus.com/bid/99148 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-1000381 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1463132 Issue Tracking
- https://c-ares.haxx.se/0616.patch x_refsource_CONFIRMMailing ListVendor Advisory
- https://c-ares.haxx.se/adv_20170620.html x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-1540 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000381
- https://www.cve.org/CVERecord?id=CVE-2017-1000381
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/99148 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-1000381 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1463132 | Issue Tracking | |
| https://c-ares.haxx.se/0616.patch | x_refsource_CONFIRMMailing ListVendor Advisory | |
| https://c-ares.haxx.se/adv_20170620.html | x_refsource_CONFIRMVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-1540 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000381 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000381 |
Change history (0)
No recorded changes yet.