CVE-2020-22217
Summary
| CVE | CVE-2020-22217 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-22 19:16:00 UTC |
| Updated | 2023-10-30 17:47:00 UTC |
| Description | Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 3567-1] c-ares security update | MLIST | lists.debian.org | |
| read-heap-buffer-overflow in ares_parse_soa_reply() · Issue #333 · c-ares/c-ares · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161189 Oracle Enterprise Linux Security Update for c-ares (ELSA-2023-7207)
- 199761 Ubuntu Security Notification for c-ares Vulnerability (USN-6376-1)
- 242447 Red Hat Update for c-ares (RHSA-2023:7207)
- 242750 Red Hat Update for c-ares (RHSA-2024:0419)
- 242802 Red Hat Update for c-ares (RHSA-2024:0578)
- 6000147 Debian Security Update for c-ares (DLA 3567-1)
- 754881 SUSE Enterprise Linux Security Update for libcares2 (SUSE-SU-2023:3690-1)
- 907722 Common Base Linux Mariner (CBL-Mariner) Security Update for python-gevent (28597-1)
- 941455 AlmaLinux Security Update for c-ares (ALSA-2023:7207)
- 961083 Rocky Linux Security Update for c-ares (RLSA-2023:7207)