Out-of-bounds read in c-ares - CVE-2024-25629
Published: February 26, 2024
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The
vulnerability exists due to a boundary error within the
ares__read_line() function when parsing local configuration files, such
as `/etc/resolv.conf`, `/etc/nsswitch.conf`, or `HOSTALIASES` file. A
local user can insert a NULL character as the first character in a new
line into one of the configuration files and crash the application.
Affected software
Amazon Linux AMI
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
openEuler
Fedora
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Storage Ceph
Traffix SDC
Nessus Network Monitor
IBM DataPower Gateway
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libc-ares2 (Ubuntu package)
c-ares-devel
c-ares
c-ares-help
c-ares-debugsource
c-ares-debuginfo
nodejs-nodemon
npm
nodejs (Red Hat package)
nodejs
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs20
nodejs-packaging
nodejs-packaging-bundler
Red Hat Advanced Cluster Security for Kubernetes
App Connect Enterprise Certified Container
IBM Qradar SIEM
IBM QRadar Network Packet Capture
IBM App Connect Enterprise
How to mitigate CVE-2024-25629
Cloud Pak for Network Automation - update to 2.7.4
Nessus Network Monitor - update to 6.4.0
IBM DataPower Gateway - addressed in versions 10.5.0.19, 10.6.0.7, 10.6.5.0
libc-ares2 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.15.0-1ubuntu0.5, 1.18.1-1ubuntu0.22.04.3, 1.19.1-3ubuntu0.1
c-ares-devel - update to 1.13.0-11
c-ares - update to 1.13.0-11
c-ares - addressed in versions 1.16.1-9, 1.18.1-8
c-ares-help - addressed in versions 1.16.1-9, 1.18.1-8
c-ares-devel - addressed in versions 1.16.1-9, 1.18.1-8
c-ares-debugsource - addressed in versions 1.16.1-9, 1.18.1-8
c-ares-debuginfo - addressed in versions 1.16.1-9, 1.18.1-8
c-ares - update to 1.19.0-1
c-ares - addressed in versions 1.28.0-1.fc38, 1.28.0-1.fc39, 1.28.0-1.fc40, 1.28.1-1.fc38, 1.28.1-1.fc39, 1.28.1-1.fc40
nodejs-nodemon - update to 3.0.1-1
Red Hat Advanced Cluster Security for Kubernetes - update to 4.5.0
IBM Cloud Pak for Watson AIOps - update to 4.6.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33, 4.15.21, 4.16.15, 4.17.0
App Connect Enterprise Certified Container - addressed in versions 5.0.18, 11.6.0
Storage Ceph - update to 7.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF03
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 10
npm - update to 10.5.0-1.18.20.2.1.0.1
IBM App Connect Enterprise - update to 12.0.12.0
nodejs (Red Hat package) - addressed in versions 16.20.2-6.el9_2.3, 16.20.2-8.el9_4, 16.20.2-9.el9_0
nodejs - update to 18.18.2-1
nodejs-docs - update to 18.20.2-1.0.1
nodejs-full-i18n - update to 18.20.2-1.0.1
nodejs-devel - update to 18.20.2-1.0.1
nodejs - update to 18.20.2-1.0.1
nodejs20 - update to 20.11.1-1
nodejs-packaging - update to 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4
External References
Related Security Bulletins
- Local denial of service in c-ares
- Ubuntu update for c-ares
- Fedora 38 update for c-ares
- Fedora 39 update for c-ares
- Fedora 40 update for c-ares
- Fedora 39 update for c-ares
- Fedora 40 update for c-ares
- Fedora 38 update for c-ares
- Tenable Nessus Network Monitor update for third-party components
- Out-of-bounds read in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Red Hat Enterprise Linux 9 update for nodejs
- Red Hat Enterprise Linux 9 update for the nodejs:20 module
- Red Hat Enterprise Linux 8 update for the nodejs:18 module
- Red Hat Enterprise Linux 8 update for the nodejs:20 module
- Red Hat Enterprise Linux 9 update for the nodejs:18 module
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Red Hat Enterprise Linux 9 update for nodejs
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5.0
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Red Hat Enterprise Linux 9 update for nodejs
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Out-of-bounds read in IBM Storage Ceph
- Amazon Linux AMI update for nodejs
- Amazon Linux AMI update for c-ares
- Amazon Linux AMI update for nodejs20
- openEuler 22.03 LTS SP1 update for c-ares
- openEuler 22.03 LTS SP3 update for c-ares
- openEuler 20.03 LTS SP4 update for c-ares
- Denial of service in F5 Traffix SDC c-ares C library
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Anolis OS update for nodejs:18 module
- Anolis OS update for c-ares
- Multiple vulnerabilities in IBM DataPower Gateway