Alerts This Week
Warning Icon 1 770
Alerts This Week
Warning Icon 1 770

SUSE: 2023:1679-1 Important: c-ares Denial of Service Security Fix

suse
Calendar Grey May 31, 2023
Dist Suse Esm H88
This release focuses on critical vulnerability resolutions in bci/nodejs and c-ares to improve system reliability and protection.
The container bci/nodejs was updated

Summary

Advisory ID: SUSE-SU-2023:2313-1 Released: Tue May 30 09:29:25 2023 Summary: Security update for c-ares Type: security Severity: important Advisory ID: SUSE-RU-2023:2317-1 Released: Tue May 30 14:01:22 2023 Summary: Recommended update for util-linux Type: recommended Severity: moderate

References

References : 1210164 1211604 1211605 1211606 1211607 CVE-2023-31124 CVE-2023-31130

CVE-2023-31147 CVE-2023-32067

1211604,1211605,1211606,1211607,CVE-2023-31124,CVE-2023-31130,CVE-2023-31147,CVE-2023-32067

This update for c-ares fixes the following issues:

Update to version 1.19.1:

- CVE-2023-32067: 0-byte UDP payload causes Denial of Service (bsc#1211604)

- CVE-2023-31147: Insufficient randomness in generation of DNS query IDs (bsc#1211605)

- CVE-2023-31130: Buffer Underwrite in ares_inet_net_pton() (bsc#1211606)

- CVE-2023-31124: AutoTools does not set CARES_RANDOM_FILE during cross compilation (bsc#1211607)

- Fix uninitialized memory warning in test

- ares_getaddrinfo() should allow a port of 0

- Fix memory leak in ares_send() on error

- Fix comment style in ares_data.h

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:1679-1
Container Tags : bci/node:18 , bci/node:18-3.58 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-3.58 , bci/nodejs:latest
Container Release : 3.58
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here