A flaw was found in the c-ares package. The...
High severity
Unreviewed
Published
Mar 7, 2023
to the GitHub Advisory Database
•
Updated Jan 14, 2024
Description
Published by the National Vulnerability Database
Mar 6, 2023
Published to the GitHub Advisory Database
Mar 7, 2023
Last updated
Jan 14, 2024
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
References