ELA-800-1 c-ares security update

denial of service

2023-02-19
Packagec-ares
Version1.10.0-2+deb8u4 (jessie), 1.12.0-1+deb9u3 (stretch)
Related CVEs CVE-2022-4904


It was discovered that in c-ares, an asynchronous name resolver library, the config_sortlist function is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow and thus may cause a denial of service.



For Debian 8 jessie, these problems have been fixed in version 1.10.0-2+deb8u4.

For Debian 9 stretch, these problems have been fixed in version 1.12.0-1+deb9u3.

We recommend that you upgrade your c-ares packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.