c-ares: buffer overflow in config_sortlist() due to missing string length check
Published Mar 6, 2023
8.6
HIGHCVSS 3.1
EPSS 1.22%
Description
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
Affected products
- Vendor n/a Product C-Ares Defaultn/a
- Version unknownStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | C-Ares | n/a |
|
Configuration 1
- < 1.19.0
Configuration 2
- n/a
- 8.0
- 9.0
Configuration 3
- 36
No data.
Red Hat Enterprise Linux 8
c-ares-0:1.13.0-8.el8
Fixed · RHSA-2023:7116
Red Hat Enterprise Linux 8
nodejs:14-8070020230306170042.bd1311ed
Fixed · RHSA-2023:1743
Red Hat Enterprise Linux 8
nodejs:16-8070020230314140722.bd1311ed
Fixed · RHSA-2023:1582
Red Hat Enterprise Linux 8
nodejs:18-8080020230607122508.63b34585
Fixed · RHSA-2023:4035
Red Hat Enterprise Linux 8.4 Extended Update Support
nodejs:14-8040020230306170312.522a0ee4
Fixed · RHSA-2023:1533
Red Hat Enterprise Linux 8.6 Extended Update Support
nodejs:14-8060020230306170237.ad008a3a
Fixed · RHSA-2023:1742
Red Hat Enterprise Linux 8.8 Extended Update Support
c-ares-0:1.13.0-6.el8_8.3
Fixed · RHSA-2023:7543
Red Hat Enterprise Linux 9
c-ares-0:1.19.1-1.el9
Fixed · RHSA-2023:6635
Red Hat Enterprise Linux 9
c-ares-0:1.19.1-1.el9
Fixed · RHSA-2023:6635
Red Hat Enterprise Linux 9
nodejs-1:16.19.1-1.el9_2
Fixed · RHSA-2023:2655
Red Hat Enterprise Linux 9
nodejs:18-9020020230327152102.rhel9
Fixed · RHSA-2023:2654
Red Hat Enterprise Linux 9.0 Extended Update Support
c-ares-0:1.17.1-5.el9_0.2
Fixed · RHSA-2023:6291
Red Hat Enterprise Linux 9.0 Extended Update Support
nodejs-1:16.20.2-1.el9_0
Fixed · RHSA-2023:5533
Red Hat Enterprise Linux 9.2 Extended Update Support
c-ares-0:1.17.1-5.el9_2.2
Fixed · RHSA-2023:7368
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-0:3.6-2.el7
Fixed · RHSA-2023:1744
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-nodejs-0:14.21.3-2.el7
Fixed · RHSA-2023:1744
Red Hat Enterprise Linux 6
c-ares
Out of support scope
Red Hat Enterprise Linux 7
c-ares
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | c-ares-0:1.13.0-8.el8 | Fixed | RHSA-2023:7116 |
| Red Hat Enterprise Linux 8 | nodejs:14-8070020230306170042.bd1311ed | Fixed | RHSA-2023:1743 |
| Red Hat Enterprise Linux 8 | nodejs:16-8070020230314140722.bd1311ed | Fixed | RHSA-2023:1582 |
| Red Hat Enterprise Linux 8 | nodejs:18-8080020230607122508.63b34585 | Fixed | RHSA-2023:4035 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | nodejs:14-8040020230306170312.522a0ee4 | Fixed | RHSA-2023:1533 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | nodejs:14-8060020230306170237.ad008a3a | Fixed | RHSA-2023:1742 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | c-ares-0:1.13.0-6.el8_8.3 | Fixed | RHSA-2023:7543 |
| Red Hat Enterprise Linux 9 | c-ares-0:1.19.1-1.el9 | Fixed | RHSA-2023:6635 |
| Red Hat Enterprise Linux 9 | c-ares-0:1.19.1-1.el9 | Fixed | RHSA-2023:6635 |
| Red Hat Enterprise Linux 9 | nodejs-1:16.19.1-1.el9_2 | Fixed | RHSA-2023:2655 |
| Red Hat Enterprise Linux 9 | nodejs:18-9020020230327152102.rhel9 | Fixed | RHSA-2023:2654 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | c-ares-0:1.17.1-5.el9_0.2 | Fixed | RHSA-2023:6291 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | nodejs-1:16.20.2-1.el9_0 | Fixed | RHSA-2023:5533 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | c-ares-0:1.17.1-5.el9_2.2 | Fixed | RHSA-2023:7368 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-0:3.6-2.el7 | Fixed | RHSA-2023:1744 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-nodejs-0:14.21.3-2.el7 | Fixed | RHSA-2023:1744 |
| Red Hat Enterprise Linux 6 | c-ares | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | c-ares | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The severity of this vulnerability is not important but moderate because exploiting the vulnerability can lead to a disruption of the availability of an application, yet doesn’t compromise data integrity or confidentiality. The opportunity for disruption is further limited due to the requirement that an application allows an attacker to be able to input both untrusted and unvalidated data. Exploiting this flaw requires an application to use the library in such a way that would allow untrusted and unvalidated input to be passed directly to ares_set_sortlist by an attacker. In the event that this is able to occur, the impact to RHEL is limited to a crash of the application due to the protections offered by default in RHEL systems such as Stack Smashing Protection (SSP).
References (7)
- https://access.redhat.com/security/cve/CVE-2022-4904 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2168631 Issue TrackingThird Party Advisory
- https://github.com/c-ares/c-ares/issues/496 ExploitIssue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33LDNS6RPOPP36Z4MPWXALUQZXJCWJS2/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4904
- https://security.gentoo.org/glsa/202401-02 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2022-4904
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-4904 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2168631 | Issue TrackingThird Party Advisory | |
| https://github.com/c-ares/c-ares/issues/496 | ExploitIssue Tracking | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33LDNS6RPOPP36Z4MPWXALUQZXJCWJS2/ | vendor-advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-4904 | ||
| https://security.gentoo.org/glsa/202401-02 | vendor-advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-4904 |
Change history (0)
No recorded changes yet.