USN-6164-2: c-ares vulnerabilities
USN-6164-1 fixed several vulnerabilities in c-ares. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: Hannes Moesl discovered that c-ares incorrectly handled certain ipv6 addresses. An attacker could use this issue to cause c-ares to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-31130) Xiang Li discovered that c-ares incorrectly handled certain UDP packets. A remote attacker could possibly use this issue to cause c-res to crash, resulting in a denial of service. (CVE-2023-32067)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6164-2?
The severity of USN-6164-2 is not specified in the description.
What is c-ares?
c-ares is a C library for asynchronous DNS requests.
What vulnerabilities does USN-6164-2 fix?
USN-6164-2 fixes several vulnerabilities in c-ares.
How can I fix the vulnerabilities in c-ares?
To fix the vulnerabilities in c-ares, you should update to the specified version provided in the update.
Where can I find more information about USN-6164-2?
You can find more information about USN-6164-2 on the Ubuntu security website.