CVE-2023-32067: 0-byte UDP payload DoS in c-ares
0-byte UDP payload DoS in c-ares
Other sources
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.
— Ubuntu
c-ares is vulnerable to a denial of service. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
CVE-2023-32067. 0-byte UDP payload causes Denial of Service (https://github.com/c-ares/c-ares/security/advisories/GHSA-9g78-jv2r-p7vc)
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/c-aresto a version that resolves this vulnerability.Fixed in 1.14.0-1ubuntu0.2+ - Upgrade
Upgrade
ubuntu/c-aresto a version that resolves this vulnerability.Fixed in 1.10.0-3ubuntu0.2+ - Upgrade
Upgrade
ubuntu/c-aresto a version that resolves this vulnerability.Fixed in 1.19.1Fixed in 1.18.1-3 - Upgrade
Upgrade
ubuntu/c-aresto a version that resolves this vulnerability.Fixed in 1.15.0-1ubuntu0.3 - Upgrade
Upgrade
ubuntu/c-aresto a version that resolves this vulnerability.Fixed in 1.18.1-1ubuntu0.22.04.2 - Upgrade
Upgrade
ubuntu/c-aresto a version that resolves this vulnerability.Fixed in 1.18.1-1ubuntu0.22.10.2 - Upgrade
Upgrade
ubuntu/c-aresto a version that resolves this vulnerability.Fixed in 1.18.1-2ubuntu0.1 - Upgrade
Upgrade
debian/c-aresto a version that resolves this vulnerability.Fixed in 1.14.0-1+deb10u4Fixed in 1.17.1-1+deb11u3Fixed in 1.18.1-3Fixed in 1.26.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.5.1.117.1.3.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.5.1 - Upgrade
Upgrade
ubuntu/c-aresto a version that resolves this vulnerability.Fixed in 1.19.1 - Upgrade
Upgrade
ubuntu/c-aresto a version that resolves this vulnerability.Fixed in 1.18.1-3 - Upgrade
Upgrade
debian/c-aresto a version that resolves this vulnerability.Fixed in 1.14.0-1+deb10u4 - Upgrade
Upgrade
debian/c-aresto a version that resolves this vulnerability.Fixed in 1.17.1-1+deb11u3 - Upgrade
Upgrade
debian/c-aresto a version that resolves this vulnerability.Fixed in 1.18.1-3 - Upgrade
Upgrade
debian/c-aresto a version that resolves this vulnerability.Fixed in 1.26.0-1 - Upgrade
Upgrade
c-aresto a version that resolves this vulnerability.Fixed in 1.19.1 - Upgrade
Upgrade
IBM Cognos Analyticsto a version that resolves this vulnerability.Fixed in 17.5.1.117.1.3.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-32067?
CVE-2023-32067 is a vulnerability in the c-ares asynchronous resolver library that allows an attacker to cause denial of service by sending a malformed UDP packet.
What is the severity of CVE-2023-32067?
CVE-2023-32067 has a severity rating of 7 (high).
How does CVE-2023-32067 affect c-ares?
CVE-2023-32067 affects c-ares versions up to 1.19.1.
How can I fix CVE-2023-32067?
To fix CVE-2023-32067, you should update c-ares to version 1.19.1 or higher.
Where can I find more information about CVE-2023-32067?
You can find more information about CVE-2023-32067 on the Red Hat security page, the c-ares GitHub security advisories page, and the Bugzilla page.