CVE-2022-4904
Vulnerability Summary
Timeline
Description
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
CVSS Metrics
- v3.1•HIGH•Score: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
EPSS Trends
Current EPSS score: 1.22%• Percentile: 67%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
- CWE-1284•Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Affected Systems
- c-ares_project•c-ares
< 1.19.0
- debian•c-ares
< 1.17.1-1+deb11u2 | < 1.18.1-2 | < 1.18.1-2 | < 1.18.1-2
- fedoraproject•fedora
36
- redhat•enterprise_linux
8.0 | 9.0
- redhat•software_collections
na
References (5)
- https://bugzilla.redhat.com/show_bug.cgi?id=2168631
- https://github.com/c-ares/c-ares/issues/496
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33LDNS6RPOPP36Z4MPWXALUQZXJCWJS2/
- https://security.gentoo.org/glsa/202401-02
- https://security-tracker.debian.org/tracker/CVE-2022-4904