CVE-2023-31124
Summary
| CVE | CVE-2023-31124 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-25 22:15:00 UTC |
| Updated | 2023-10-31 16:05:00 UTC |
| Description | c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 38 Update: c-ares-1.19.1-1.fc38 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| Release 1.19.1 · c-ares/c-ares · GitHub |
MISC |
github.com |
|
| c-ares: Multiple Vulnerabilities (GLSA 202310-09) — Gentoo security |
MISC |
security.gentoo.org |
|
| [SECURITY] Fedora 37 Update: c-ares-1.19.1-1.fc37 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| AutoTools does not set CARES_RANDOM_FILE during cross compilation · Advisory · c-ares/c-ares · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160732 Oracle Enterprise Linux Security Update for nodejs (ELSA-2023-3586)
- 160740 Oracle Enterprise Linux Security Update for 18 (ELSA-2023-3577)
- 160788 Oracle Enterprise Linux Security Update for nodejs:16 (ELSA-2023-4034)
- 160794 Oracle Enterprise Linux Security Update for nodejs:18 (ELSA-2023-4035)
- 161099 Oracle Enterprise Linux Security Update for c-ares (ELSA-2023-6635)
- 241702 Red Hat Update for nodejs:18 (RHSA-2023:3577)
- 241724 Red Hat Update for nodejs (RHSA-2023:3586)
- 241786 Red Hat Update for rh-nodejs14-nodejs (RHSA-2023:4039)
- 241787 Red Hat Update for nodejs (RHSA-2023:4036)
- 241788 Red Hat Update for nodejs:18 (RHSA-2023:4035)
- 241790 Red Hat Update for nodejs:16 (RHSA-2023:4033)
- 241792 Red Hat Update for nodejs:16 (RHSA-2023:4034)
- 242322 Red Hat Update for c-ares security (RHSA-2023:6635)
- 284001 Fedora Security Update for c (FEDORA-2023-ae97529c00)
- 284101 Fedora Security Update for c (FEDORA-2023-520848815b)
- 355414 Amazon Linux Security Advisory for c-ares : ALAS2023-2023-198
- 356117 Amazon Linux Security Advisory for ecs-service-connect-agent : ALAS2023-2023-344
- 356246 Amazon Linux Security Advisory for ecs-service-connect-agent : ALASECS-2023-007
- 356504 Amazon Linux Security Advisory for ecs-service-connect-agent : ALAS2ECS-2023-007
- 357009 Amazon Linux Security Advisory for c-ares : ALAS2-2024-2429
- 673270 EulerOS Security Update for c-ares (EulerOS-SA-2023-2575)
- 673319 EulerOS Security Update for c-ares (EulerOS-SA-2023-2605)
- 673489 EulerOS Security Update for c-ares (EulerOS-SA-2023-2828)
- 673513 EulerOS Security Update for c-ares (EulerOS-SA-2023-2833)
- 673706 EulerOS Security Update for c-ares (EulerOS-SA-2023-3115)
- 673890 EulerOS Security Update for c-ares (EulerOS-SA-2023-2780)
- 674117 EulerOS Security Update for c-ares (EulerOS-SA-2023-2804)
- 710769 Gentoo Linux c-ares Multiple Vulnerabilities (GLSA 202310-09)
- 754046 SUSE Enterprise Linux Security Update for c-ares (SUSE-SU-2023:2313-1)
- 754083 SUSE Enterprise Linux Security Update for libcares2 (SUSE-SU-2023:2477-1)
- 754181 SUSE Enterprise Linux Security Update for nodejs16 (SUSE-SU-2023:2861-1)
- 907006 Common Base Linux Mariner (CBL-Mariner) Security Update for c-ares (26959-1)
- 941145 AlmaLinux Security Update for nodejs (ALSA-2023:3586)
- 941153 AlmaLinux Security Update for nodejs:18 (ALSA-2023:3577)
- 941168 AlmaLinux Security Update for nodejs:16 (ALSA-2023:4034)
- 941169 AlmaLinux Security Update for nodejs:18 (ALSA-2023:4035)
- 941381 AlmaLinux Security Update for c-ares (ALSA-2023:6635)
- 960945 Rocky Linux Security Update for nodejs:18 (RLSA-2023:3577)