Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2024-25629
Description:c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.
Test IDs: 1.3.6.1.4.1.25623.1.0.886506   1.3.6.1.4.1.25623.1.1.2.2024.2020   1.3.6.1.4.1.25623.1.1.2.2024.2900   1.3.6.1.4.1.25623.1.0.886778   1.3.6.1.4.1.25623.1.1.2.2024.2714   1.3.6.1.4.1.25623.1.1.2.2024.2522   1.3.6.1.4.1.25623.1.1.12.2024.6676.1   1.3.6.1.4.1.25623.1.1.2.2024.2458   1.3.6.1.4.1.25623.1.1.2.2024.2881   1.3.6.1.4.1.25623.1.1.2.2025.1091   1.3.6.1.4.1.25623.1.1.2.2024.2573   1.3.6.1.4.1.25623.1.1.4.2024.1135.1   1.3.6.1.4.1.25623.1.1.2.2024.2547   1.3.6.1.4.1.25623.1.1.2.2024.2824   1.3.6.1.4.1.25623.1.1.2.2024.2748   1.3.6.1.4.1.25623.1.1.2.2024.2766   1.3.6.1.4.1.25623.1.0.886524   1.3.6.1.4.1.25623.1.1.2.2024.2731   1.3.6.1.4.1.25623.1.1.2.2024.2808   1.3.6.1.4.1.25623.1.1.2.2024.2498   1.3.6.1.4.1.25623.1.1.2.2025.1104   1.3.6.1.4.1.25623.1.1.10.2024.0051   1.3.6.1.4.1.25623.1.0.856056  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2024-25629
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GX37LFPFQ3T6FFMMFYQTEGIQXXN7F27U/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CSCMTSPDIE2UHU34TIXQQHZ6JTE3Y3VF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2P76QYINQNPEHUTEEDOUYIRZ2X6UVZ5K/
https://github.com/c-ares/c-ares/commit/a804c04ddc8245fc8adf0e92368709639125e183
https://github.com/c-ares/c-ares/commit/a804c04ddc8245fc8adf0e92368709639125e183
https://github.com/c-ares/c-ares/security/advisories/GHSA-mg26-v6qh-x48q
https://github.com/c-ares/c-ares/security/advisories/GHSA-mg26-v6qh-x48q




© 1998-2025 E-Soft Inc. All rights reserved.