Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 16.10 USN-3143-1 Critical: c-ares Denial of Service

ubuntu
Calendar Grey November 30, 2016
Scroller Ubuntu
Versions of Ubuntu prior to 16.10 are vulnerable to the c-ares flaw, increasing the likelihood of system crashes and potential remote code execution threats.
c-ares could be made to crash or run programs if it processed a specially crafted hostname.

Summary

c-ares could be made to crash or run programs if it processed a specially

crafted hostname.

Software Description:

- c-ares: library for asynchronous name resolves

Details:

Gzob Qq discovered that c-ares incorrectly handled certain hostnames. A

remote attacker could use this issue to cause applications using c-ares to

crash, resulting in a denial of service, or possibly execute arbitrary

code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
  libc-ares2                      1.11.0-1ubuntu0.1

Ubuntu 16.04 LTS:
  libc-ares2                      1.10.0-3ubuntu0.1

Ubuntu 14.04 LTS:
  libc-ares2                      1.10.0-2ubuntu0.1

Ubuntu 12.04 LTS:
  libc-ares2                      1.7.5-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3143-1

CVE-2016-5180

Severity
critical
Lowest
Low
Medium
High
Critical

November 30, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.