Out-of-bounds read in c-ares - CVE-2024-25629

 

Out-of-bounds read in c-ares - CVE-2024-25629

Published: February 26, 2024


Vulnerability identifier: #VU86807
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25629
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the ares__read_line() function when parsing local configuration files, such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, or `HOSTALIASES` file. A local user can insert a NULL character as the first character in a new line into one of the configuration files and crash the application.


Affected software

c-ares
Amazon Linux AMI
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
openEuler
Fedora
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Storage Ceph
Traffix SDC
Nessus Network Monitor
IBM DataPower Gateway
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libc-ares2 (Ubuntu package)
c-ares-devel
c-ares
c-ares-help
c-ares-debugsource
c-ares-debuginfo
nodejs-nodemon
npm
nodejs (Red Hat package)
nodejs
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs20
nodejs-packaging
nodejs-packaging-bundler
Red Hat Advanced Cluster Security for Kubernetes
App Connect Enterprise Certified Container
IBM Qradar SIEM
IBM QRadar Network Packet Capture
IBM App Connect Enterprise

How to mitigate CVE-2024-25629

Install updates from vendor's website.

c-ares - update to 1.27.0
Cloud Pak for Network Automation - update to 2.7.4
Nessus Network Monitor - update to 6.4.0
IBM DataPower Gateway - addressed in versions 10.5.0.19, 10.6.0.7, 10.6.5.0
libc-ares2 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.15.0-1ubuntu0.5, 1.18.1-1ubuntu0.22.04.3, 1.19.1-3ubuntu0.1
c-ares-devel - update to 1.13.0-11
c-ares - update to 1.13.0-11
c-ares - addressed in versions 1.16.1-9, 1.18.1-8
c-ares-help - addressed in versions 1.16.1-9, 1.18.1-8
c-ares-devel - addressed in versions 1.16.1-9, 1.18.1-8
c-ares-debugsource - addressed in versions 1.16.1-9, 1.18.1-8
c-ares-debuginfo - addressed in versions 1.16.1-9, 1.18.1-8
c-ares - update to 1.19.0-1
c-ares - addressed in versions 1.28.0-1.fc38, 1.28.0-1.fc39, 1.28.0-1.fc40, 1.28.1-1.fc38, 1.28.1-1.fc39, 1.28.1-1.fc40
nodejs-nodemon - update to 3.0.1-1
Red Hat Advanced Cluster Security for Kubernetes - update to 4.5.0
IBM Cloud Pak for Watson AIOps - update to 4.6.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33, 4.15.21, 4.16.15, 4.17.0
App Connect Enterprise Certified Container - addressed in versions 5.0.18, 11.6.0
Storage Ceph - update to 7.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF03
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 10
npm - update to 10.5.0-1.18.20.2.1.0.1
IBM App Connect Enterprise - update to 12.0.12.0
nodejs (Red Hat package) - addressed in versions 16.20.2-6.el9_2.3, 16.20.2-8.el9_4, 16.20.2-9.el9_0
nodejs - update to 18.18.2-1
nodejs-docs - update to 18.20.2-1.0.1
nodejs-full-i18n - update to 18.20.2-1.0.1
nodejs-devel - update to 18.20.2-1.0.1
nodejs - update to 18.20.2-1.0.1
nodejs20 - update to 20.11.1-1
nodejs-packaging - update to 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4

External References

Related Security Bulletins