USN-6164-1: c-ares vulnerabilities
Hannes Moesl discovered that c-ares incorrectly handled certain ipv6 addresses. An attacker could use this issue to cause c-ares to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-31130) Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A remote attacker could possibly use this issue to cause c-res to crash, resulting in a denial of service. (CVE-2023-32067)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for c-ares?
The vulnerability ID for c-ares is CVE-2023-31130.
What is the severity of CVE-2023-31130?
The severity of CVE-2023-31130 is not specified in the information provided.
How does the c-ares vulnerability CVE-2023-31130 impact the system?
The c-ares vulnerability CVE-2023-31130 could cause c-ares to crash, resulting in a denial of service, or possibly execute arbitrary code.
How do I fix the c-ares vulnerability CVE-2023-31130?
To fix the c-ares vulnerability CVE-2023-31130, update to version 1.18.1-2ubuntu0.1 if using Ubuntu 23.04, version 1.18.1-1ubuntu0.22.10.2 if using Ubuntu 22.10, version 1.18.1-1ubuntu0.22.04.2 if using Ubuntu 22.04, or version 1.15.0-1ubuntu0.3 if using Ubuntu 20.04.
Where can I find more information about the c-ares vulnerabilities?
You can find more information about the c-ares vulnerabilities at the following references: [CVE-2023-31130](https://ubuntu.com/security/CVE-2023-31130), [CVE-2023-32067](https://ubuntu.com/security/CVE-2023-32067), [USN-6164-2](https://ubuntu.com/security/notices/USN-6164-2).