QID 356347
Date Published: 2023-10-18
QID 356347: Amazon Linux Security Advisory for c-ares : AL2012-2023-450
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2023-32067:
Denial of Service.
Attack Steps:
The target resolver sends a query
The attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver
The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. (this is only valid for TCP connections, UDP is connection-less)
Current resolution fails, DoS attack is achieved.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 356347
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-450 | Amazon Linux Bare Metal |
|