Critical severity9.8NVD Advisory· Published Oct 3, 2016· Updated May 6, 2026
CVE-2016-5180
CVE-2016-5180
Description
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- rhn.redhat.com/errata/RHSA-2017-0002.htmlnvd
- www.debian.org/security/2016/dsa-3682nvd
- www.securityfocus.com/bid/93243nvd
- www.ubuntu.com/usn/USN-3143-1nvd
- c-ares.haxx.se/CVE-2016-5180.patchnvd
- c-ares.haxx.se/adv_20160929.htmlnvd
- googlechromereleases.blogspot.in/2016/09/stable-channel-updates-for-chrome-os.htmlnvd
- security.gentoo.org/glsa/201701-28nvd
- source.android.com/security/bulletin/2017-01-01.htmlnvd
News mentions
0No linked articles in our index yet.