Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Ubuntu 21.04: USN-5034-1 Critical: c-ares Domain Hijacking Risk

ubuntu
Calendar Grey August 10, 2021
Dist Ubuntu Esm H88
C-ares security flaw leads to improper hostname verification, posing threats for domain takeover on Debian platforms.
c-ares could be made to return wrong domains.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: libc-ares2 1.17.1-1ubuntu0.1 Ubuntu 20.04 LTS: libc-ares2 1.15.0-1ubuntu0.1 Ubuntu 18.04 LTS: libc-ares2 1.14.0-1ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5034-1

CVE-2021-3672

Severity
critical
Lowest
Low
Medium
High
Critical

August 10, 2021

Package Information

https://launchpad.net/ubuntu/+source/c-ares/1.17.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/c-ares/1.15.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/c-ares/1.14.0-1ubuntu0.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here