Unrated severityNVD Advisory· Published Feb 23, 2024· Updated Feb 13, 2025
c-ares out of bounds read in ares__read_line()
CVE-2024-25629
Description
c-ares is a C library for asynchronous DNS requests. ares__read_line() is used to parse local configuration files such as /etc/resolv.conf, /etc/nsswitch.conf, the HOSTALIASES file, and if using a c-ares version prior to 1.27.0, the /etc/hosts file. If any of these configuration files has an embedded NULL character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.
Affected products
32- osv-coords31 versionspkg:apk/chainguard/c-arespkg:apk/chainguard/c-ares-devpkg:apk/chainguard/c-ares-docpkg:apk/wolfi/c-arespkg:apk/wolfi/c-ares-devpkg:apk/wolfi/c-ares-docpkg:rpm/almalinux/c-arespkg:rpm/almalinux/c-ares-develpkg:rpm/almalinux/nodejspkg:rpm/almalinux/nodejs-develpkg:rpm/almalinux/nodejs-docspkg:rpm/almalinux/nodejs-full-i18npkg:rpm/almalinux/nodejs-libspkg:rpm/almalinux/nodejs-nodemonpkg:rpm/almalinux/nodejs-packagingpkg:rpm/almalinux/nodejs-packaging-bundlerpkg:rpm/almalinux/npmpkg:rpm/opensuse/c-ares&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/c-ares&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/c-ares&distro=openSUSE%20Leap%20Micro%205.4pkg:rpm/opensuse/c-ares&distro=openSUSE%20Tumbleweedpkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/libcares2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/libcares2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/libcares2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/libcares2&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5
< 1.27.0-r0+ 30 more
- (no CPE)range: < 1.27.0-r0
- (no CPE)range: < 1.27.0-r0
- (no CPE)range: < 1.27.0-r0
- (no CPE)range: < 1.27.0-r0
- (no CPE)range: < 1.27.0-r0
- (no CPE)range: < 1.27.0-r0
- (no CPE)range: < 1.19.1-2.el9_4
- (no CPE)range: < 1.19.1-2.el9_4
- (no CPE)range: < 1:20.12.2-2.module_el8.9.0+3827+11b91f3e
- (no CPE)range: < 1:20.12.2-2.module_el8.9.0+3827+11b91f3e
- (no CPE)range: < 1:20.12.2-2.module_el8.9.0+3827+11b91f3e
- (no CPE)range: < 1:20.12.2-2.module_el8.9.0+3827+11b91f3e
- (no CPE)range: < 1:16.20.2-8.el9_4
- (no CPE)range: < 3.0.1-1.module_el8.9.0+3731+490e3ce5
- (no CPE)range: < 2021.06-4.module_el8.9.0+3684+11b9e959
- (no CPE)range: < 2021.06-4.module_el8.9.0+3684+11b9e959
- (no CPE)range: < 1:10.5.0-1.20.12.2.2.module_el8.9.0+3827+11b91f3e
- (no CPE)range: < 1.19.1-150000.3.26.1
- (no CPE)range: < 1.19.1-150000.3.26.1
- (no CPE)range: < 1.19.1-150000.3.26.1
- (no CPE)range: < 1.27.0-1.1
- (no CPE)range: < 1.19.1-150000.3.26.1
- (no CPE)range: < 1.19.1-150000.3.26.1
- (no CPE)range: < 1.19.1-150000.3.26.1
- (no CPE)range: < 1.19.1-150000.3.26.1
- (no CPE)range: < 1.19.1-150000.3.26.1
- (no CPE)range: < 1.19.1-150000.3.26.1
- (no CPE)range: < 1.9.1-9.21.1
- (no CPE)range: < 1.9.1-9.21.1
- (no CPE)range: < 1.9.1-9.21.1
- (no CPE)range: < 1.9.1-9.21.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/c-ares/c-ares/commit/a804c04ddc8245fc8adf0e92368709639125e183mitrex_refsource_MISC
- github.com/c-ares/c-ares/security/advisories/GHSA-mg26-v6qh-x48qmitrex_refsource_CONFIRM
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2P76QYINQNPEHUTEEDOUYIRZ2X6UVZ5K/mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CSCMTSPDIE2UHU34TIXQQHZ6JTE3Y3VF/mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GX37LFPFQ3T6FFMMFYQTEGIQXXN7F27U/mitre
News mentions
0No linked articles in our index yet.