Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian Security Advisory DLA-998-1: Critical Memory Leak Fix for c-ares

debian lts
Calendar Grey June 22, 2017
Dist Debian Esm H88
The Debian LTS team has issued a patch for c-ares to rectify vulnerabilities related to CVE-2017-1000382, resolving concerns over improper memory access.
CVE-2017-1000381 The c-ares function ares_parse_naptr_reply(), which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the...

Summary


For Debian 7 "Wheezy", these problems have been fixed in version
1.9.1-3+deb7u2.

We recommend that you upgrade your c-ares packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: c-ares
Version: 1.9.1-3+deb7u2
CVE ID: CVE-2017-1000381

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here