VYPR
High severity7.5NVD Advisory· Published Jul 7, 2017· Updated May 13, 2026

CVE-2017-1000381

CVE-2017-1000381

Description

The c-ares function ares_parse_naptr_reply(), which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.

Affected products

9
  • C Ares/C Ares5 versions
    cpe:2.3:a:c-ares:c-ares:1.10.0:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:c-ares:c-ares:1.10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:c-ares:c-ares:1.12.0:*:*:*:*:*:*:*
    • cpe:2.3:a:c-ares:c-ares:1.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:c-ares:c-ares:1.9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:c-ares:c-ares:1.9.1:*:*:*:*:*:*:*
  • cpe:2.3:a:c-ares_project:c-ares:1.11.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:c-ares_project:c-ares:1.11.0:*:*:*:*:*:*:*
    • cpe:2.3:a:c-ares_project:c-ares:1.11.0:rc1:*:*:*:*:*:*
  • Node.js/Node.js2 versions
    cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*range: >=4.0.0,<=4.1.2
    • cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*range: >=4.2.0,<4.8.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.