High severity7.5NVD Advisory· Published Jul 7, 2017· Updated May 13, 2026
CVE-2017-1000381
CVE-2017-1000381
Description
The c-ares function ares_parse_naptr_reply(), which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.
Affected products
9cpe:2.3:a:c-ares_project:c-ares:1.11.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:c-ares_project:c-ares:1.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:c-ares_project:c-ares:1.11.0:rc1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/99148nvdThird Party AdvisoryVDB Entry
- c-ares.haxx.se/0616.patchnvdMailing ListVendor Advisory
- c-ares.haxx.se/adv_20170620.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.