Package | c-ares |
---|---|
Version | 1.10.0-2+deb8u4 (jessie), 1.12.0-1+deb9u3 (stretch) |
Related CVEs | CVE-2022-4904 |
It was discovered that in c-ares, an asynchronous name resolver library, the config_sortlist function is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow and thus may cause a denial of service.
For Debian 8 jessie, these problems have been fixed in version 1.10.0-2+deb8u4.
For Debian 9 stretch, these problems have been fixed in version 1.12.0-1+deb9u3.
We recommend that you upgrade your c-ares packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.