Out-of-bounds read in c-ares - CVE-2017-1000381
Published: July 18, 2017 / Updated: January 6, 2025
c-ares
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack and gain access to potentially sensitive data.
The vulnerability exists due to a boundary error in ares_parse_naptr_reply() function when processing NAPTR responses. A remote attacker can send a specially crafted DNS response to vulnerable application and perform denial of service attack or gain access to potentially sensitive data.